2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27148MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to...
CVE-2023-46288MEDIUM4.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air...
CVE-2023-43045HIGH7.5IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized action...
CVE-2023-38722MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulne...
CVE-2023-46331MEDIUM5.5WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fa...
CVE-2023-37532MEDIUM4.3HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files o...
CVE-2023-46332MEDIUM5.5WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
CVE-2023-46122HIGH7.1sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of...
CVE-2023-43067MEDIUM6.5 Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploi...
CVE-2023-43066HIGH7.8 Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local atta...
CVE-2023-5718MEDIUM4.3The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa...
CVE-2023-46127MEDIUM5.4Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated clien...
CVE-2023-43074HIGH7.5 Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially...
CVE-2023-43065MEDIUM5.4 Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can expl...
CVE-2023-42295HIGH8.8An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service...
CVE-2023-28805CRITICAL9.8An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue ...
CVE-2023-28804MEDIUM5.3An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing ...
CVE-2023-28803MEDIUM6.5An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on ...
CVE-2023-28797HIGH7.3Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk....
CVE-2023-28796HIGH7.8Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injectio...
CVE-2023-28795HIGH7.8Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process....
CVE-2023-28793HIGH7.8Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. Th...
CVE-2023-5246HIGH8.8Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074,...
CVE-2023-45802MEDIUM5.9When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were...
CVE-2023-43622HIGH7.5An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now