2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25223 | HIGH | 7.2 | 0.8% | Mar 7, 2023 | CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. |
| CVE-2023-27522 | HIGH | 7.5 | 2.1% | Mar 7, 2023 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: ... |
| CVE-2023-23554 | HIGH | 8.8 | 0.9% | Mar 7, 2023 | Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm... |
| CVE-2023-1211 | HIGH | 7.2 | 3.0% | Mar 7, 2023 | SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. |
| CVE-2023-27891 | HIGH | 7.5 | 0.6% | Mar 6, 2023 | rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.... |
| CVE-2023-26601 | HIGH | 7.5 | 34.1% | Mar 6, 2023 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Su... |
| CVE-2023-24217 | HIGH | 8.8 | 4.5% | Mar 6, 2023 | AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. |
| CVE-2023-1161 | HIGH | 7.1 | 0.6% | Mar 6, 2023 | ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via pac... |
| CVE-2023-0093 | HIGH | 8.8 | 1.1% | Mar 6, 2023 | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third p... |
| CVE-2023-24763 | HIGH | 8.8 | 0.9% | Mar 6, 2023 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2... |
| CVE-2023-23939 | HIGH | 7 | 0.4% | Mar 6, 2023 | Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3... |
| CVE-2023-25304 | HIGH | 7.8 | 0.4% | Mar 6, 2023 | An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack ... |
| CVE-2023-24789 | HIGH | 8.8 | 0.8% | Mar 6, 2023 | jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report c... |
| CVE-2023-1191 | HIGH | 7.2 | 0.9% | Mar 6, 2023 | A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/Temp... |
| CVE-2023-1190 | HIGH | 7.8 | 0.4% | Mar 6, 2023 | A vulnerability was found in xiaozhuai imageinfo up to 3.0.3. It has been rated as problematic. Affected by this issue i... |
| CVE-2023-1185 | HIGH | 8.8 | 0.7% | Mar 6, 2023 | A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of t... |
| CVE-2023-1184 | HIGH | 8.8 | 0.7% | Mar 6, 2023 | A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is so... |
| CVE-2023-26111 | HIGH | 7.5 | 1.5% | Mar 6, 2023 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directo... |
| CVE-2023-26107 | HIGH | 7.8 | 0.4% | Mar 6, 2023 | All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without saniti... |
| CVE-2023-26106 | HIGH | 7.5 | 0.9% | Mar 6, 2023 | All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file. |
| CVE-2023-22424 | HIGH | 7.8 | 0.3% | Mar 6, 2023 | Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Vers... |
| CVE-2023-22421 | HIGH | 7.8 | 0.3% | Mar 6, 2023 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2023-22419 | HIGH | 7.8 | 0.2% | Mar 6, 2023 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2023-22335 | HIGH | 7.5 | 0.7% | Mar 6, 2023 | Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier... |
| CVE-2023-27635 | HIGH | 7.8 | 0.4% | Mar 5, 2023 | debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a cr... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now