2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42643 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42642 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42641 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42640 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42639 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42638 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42637 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42636 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42635 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42634 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42633 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42632 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42631 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-1720 | HIGH | 8 | 0.9% | Nov 1, 2023 | Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaSc... |
| CVE-2023-1719 | CRITICAL | 9.8 | 5.0% | Nov 1, 2023 | Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers... |
| CVE-2023-1718 | HIGH | 7.5 | 24.1% | Nov 1, 2023 | Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated... |
| CVE-2023-1717 | CRITICAL | 9.6 | 1.1% | Nov 1, 2023 | Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 al... |
| CVE-2023-1716 | CRITICAL | 9.6 | 0.7% | Nov 1, 2023 | Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrar... |
| CVE-2023-1715 | MEDIUM | 5.4 | 0.6% | Nov 1, 2023 | A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass... |
| CVE-2023-1714 | HIGH | 8.8 | 1.4% | Nov 1, 2023 | Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote au... |
| CVE-2023-1713 | HIGH | 8.8 | 1.2% | Nov 1, 2023 | Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apa... |
| CVE-2023-4198 | MEDIUM | 6.5 | 0.6% | Nov 1, 2023 | Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database tabl... |
| CVE-2023-4197 | HIGH | 8.8 | 32.8% | Nov 1, 2023 | Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when c... |
| CVE-2023-5516 | MEDIUM | 5.3 | 0.4% | Nov 1, 2023 | Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, d... |
| CVE-2023-5515 | MEDIUM | 5.3 | 0.4% | Nov 1, 2023 | The responses for web queries with certain parameters disclose internal path of resources. This information can be used... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now