2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42643MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42642MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42641MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42640MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42639MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42638MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42637MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42636MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42635MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42634MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42633MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42632MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-42631MEDIUM5.5In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n...
CVE-2023-1720HIGH8Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaSc...
CVE-2023-1719CRITICAL9.8Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers...
CVE-2023-1718HIGH7.5 Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated...
CVE-2023-1717CRITICAL9.6 Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 al...
CVE-2023-1716CRITICAL9.6 Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrar...
CVE-2023-1715MEDIUM5.4 A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass...
CVE-2023-1714HIGH8.8Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote au...
CVE-2023-1713HIGH8.8Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apa...
CVE-2023-4198MEDIUM6.5Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database tabl...
CVE-2023-4197HIGH8.8Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when c...
CVE-2023-5516MEDIUM5.3 Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, d...
CVE-2023-5515MEDIUM5.3 The responses for web queries with certain parameters disclose internal path of resources. This information can be used...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now