2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5789MEDIUM4.8A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown fu...
CVE-2023-5624HIGH7.2 Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow a...
CVE-2023-5623HIGH7.8 NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary...
CVE-2023-5622HIGH8.8 Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORI...
CVE-2023-46666MEDIUM6.5An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepo...
CVE-2023-45317HIGH8.8 The application interface allows users to perform certain actions via HTTP requests without performing any validity ch...
CVE-2023-45228MEDIUM6.5 The application suffers from improper access control when editing users. A user with read permissions can manipulate ...
CVE-2023-43208CRITICAL9.8NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that ...
CVE-2023-42769CRITICAL9.8The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker ...
CVE-2023-41966HIGH8.8 The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileg...
CVE-2023-5787HIGH8.8A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical...
CVE-2023-5786HIGH8.8A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability...
CVE-2023-5785HIGH7.5A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This...
CVE-2023-5784CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t...
CVE-2023-46450MEDIUM5.4Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the ...
CVE-2023-46449HIGH8.8Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbit...
CVE-2023-46238MEDIUM5.4ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various i...
CVE-2023-46234HIGH7.5browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based...
CVE-2023-45869CRITICAL9ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a hi...
CVE-2023-45868HIGH8.1The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high...
CVE-2023-45867MEDIUM6.5ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the S...
CVE-2023-5783HIGH7.5A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability i...
CVE-2023-5782CRITICAL9.8A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown funct...
CVE-2023-46090MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.
CVE-2023-41096MEDIUM6.1Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High module...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now