2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41101CRITICAL9.8An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not ...
CVE-2023-39548HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39547HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39546HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39545HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39544HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-38324MEDIUM5.3An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authent...
CVE-2023-38322HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference th...
CVE-2023-38320HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer derefere...
CVE-2023-38316CRITICAL9.8An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, a...
CVE-2023-38315HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer deref...
CVE-2023-38314MEDIUM6.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthent...
CVE-2023-38313HIGH7.5An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can b...
CVE-2023-48659CRITICAL9.8An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
CVE-2023-48658CRITICAL9.8An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, un...
CVE-2023-48657CRITICAL9.8An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
CVE-2023-48656CRITICAL9.8An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
CVE-2023-48655CRITICAL9.8An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filt...
CVE-2023-47675HIGH7.2CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary ...
CVE-2023-47283MEDIUM4.9Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati...
CVE-2023-42428MEDIUM6.5Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati...
CVE-2023-38130HIGH8.1Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to d...
CVE-2023-48649MEDIUM5.4Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.
CVE-2023-48648CRITICAL9.8Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insec...
CVE-2023-48031CRITICAL9.8OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attac...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now