2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46664CRITICAL9.1 Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides ...
CVE-2023-46663HIGH8.1 Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protecte...
CVE-2023-39726CRITICAL9.8An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the ter...
CVE-2023-33559HIGH8.8A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrar...
CVE-2023-33558HIGH7.5An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to...
CVE-2023-5804CRITICAL9.8A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue...
CVE-2023-5754CRITICAL9.8 Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote passw...
CVE-2023-46662HIGH7.5 Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcem...
CVE-2023-46661CRITICAL9.8 Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. ...
CVE-2023-44267CRITICAL9.8Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of ...
CVE-2023-39936HIGH7.8 In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsi...
CVE-2023-39427HIGH7.8 In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lac...
CVE-2023-0897CRITICAL9.8 Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force ...
CVE-2023-31416MEDIUM5.3Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requ...
CVE-2023-5796HIGH8.8A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unk...
CVE-2023-5795HIGH8.8A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability ...
CVE-2023-5794CRITICAL9.8A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected...
CVE-2023-5793MEDIUM5.4A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCr...
CVE-2023-46435CRITICAL9.8Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_servic...
CVE-2023-31419HIGH7.5A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause...
CVE-2023-31418HIGH7.5An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user...
CVE-2023-31417MEDIUM4.4Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found ...
CVE-2023-5792CRITICAL9.8A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability aff...
CVE-2023-5791MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an ...
CVE-2023-5790CRITICAL9.8A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now