2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46345HIGH7.5Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
CVE-2023-43906MEDIUM6.1Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVE-2023-43905HIGH7.5Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecifi...
CVE-2023-30969MEDIUM6.5The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authen...
CVE-2023-30967HIGH7.5Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unaut...
CVE-2023-46584CRITICAL9.8SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker t...
CVE-2023-46583MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attack...
CVE-2023-46232MEDIUM5.3era-compiler-vyper is the EraVM Vyper compiler for zkSync Era, a layer 2 rollup that uses zero-knowledge proofs to scale...
CVE-2023-38849HIGH7.5An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
CVE-2023-38848HIGH7.5An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET r...
CVE-2023-38847HIGH7.5An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET reque...
CVE-2023-38846HIGH7.5An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
CVE-2023-38845HIGH7.5An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via craf...
CVE-2023-46233CRITICAL9.1crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker th...
CVE-2023-46137MEDIUM5.3Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP r...
CVE-2023-46134CRITICAL9.8D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to v...
CVE-2023-46133CRITICAL9.1CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF...
CVE-2023-45137MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.plat...
CVE-2023-5574HIGH7A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy confi...
CVE-2023-5380MEDIUM4.7A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy config...
CVE-2023-5367HIGH7.8A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buff...
CVE-2023-5044HIGH8.8Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVE-2023-5043HIGH8.8Ingress nginx annotation injection causes arbitrary command execution.
CVE-2023-46424CRITICAL9.8TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-46423CRITICAL9.8TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now