2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-25223HIGH7.2CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
CVE-2023-27522HIGH7.5HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: ...
CVE-2023-23554HIGH8.8Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm...
CVE-2023-1211HIGH7.2SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-27891HIGH7.5rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4....
CVE-2023-26601HIGH7.5Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Su...
CVE-2023-24217HIGH8.8AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
CVE-2023-1161HIGH7.1ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via pac...
CVE-2023-0093HIGH8.8Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third p...
CVE-2023-24763HIGH8.8In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2...
CVE-2023-23939HIGH7Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3...
CVE-2023-25304HIGH7.8An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack ...
CVE-2023-24789HIGH8.8jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report c...
CVE-2023-1191HIGH7.2A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/Temp...
CVE-2023-1190HIGH7.8A vulnerability was found in xiaozhuai imageinfo up to 3.0.3. It has been rated as problematic. Affected by this issue i...
CVE-2023-1185HIGH8.8A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of t...
CVE-2023-1184HIGH8.8A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is so...
CVE-2023-26111HIGH7.5All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directo...
CVE-2023-26107HIGH7.8All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without saniti...
CVE-2023-26106HIGH7.5All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
CVE-2023-22424HIGH7.8Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Vers...
CVE-2023-22421HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2023-22419HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2023-22335HIGH7.5Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier...
CVE-2023-27635HIGH7.8debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a cr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now