2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-23692HIGH8.8 Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacke...
CVE-2023-22572HIGH7.8 Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in chan...
CVE-2023-24977HIGH7.5Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1....
CVE-2023-23846HIGH7.5Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsi...
CVE-2023-20856HIGH8.8VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the v...
CVE-2023-0524HIGH8.8As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This co...
CVE-2023-0454HIGH8.1OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. Th...
CVE-2023-24956HIGH8.8Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php...
CVE-2023-0341HIGH7.8A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker t...
CVE-2023-22611HIGH7.5A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information ...
CVE-2023-22610HIGH7.5 A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server...
CVE-2023-24829HIGH8.8Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe...
CVE-2023-22315HIGH7.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does...
CVE-2023-24830HIGH7.5Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench ...
CVE-2023-0512HIGH7.8Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
CVE-2023-0266HIGH7A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 i...
CVE-2023-0240HIGH7.8There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading ...
CVE-2023-0474HIGH8.8Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install...
CVE-2023-0473HIGH8.8Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially ex...
CVE-2023-0472HIGH8.8Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap ...
CVE-2023-0471HIGH8.8Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit...
CVE-2023-24623HIGH7.5Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter...
CVE-2023-0564HIGH7.5Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0561HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System ...
CVE-2023-0560HIGH7.2A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management Sy...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now