2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42435HIGH8.8 The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to pe...
CVE-2023-41089HIGH8.8 The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to ...
CVE-2023-41088MEDIUM6.5 The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which ...
CVE-2023-40153MEDIUM6.1 The affected product is vulnerable to a cross-site scripting vulnerability, which could allow an attacker to access the...
CVE-2023-5059HIGH7.8 Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead...
CVE-2023-39431HIGH7.8 Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an ...
CVE-2023-38128HIGH7.8An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specia...
CVE-2023-38127HIGH7.8An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted docum...
CVE-2023-35986HIGH7.8 Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a sta...
CVE-2023-34366HIGH7.8A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A special...
CVE-2023-45665Rejected reason: This CVE is a duplicate of another CVE.
CVE-2023-45281MEDIUM6.1An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
CVE-2023-45278CRITICAL9.1Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbi...
CVE-2023-45277HIGH7.5Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of th...
CVE-2023-35126HIGH7.8An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles...
CVE-2023-46033MEDIUM6.8D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The...
CVE-2023-5654MEDIUM6.5The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in ...
CVE-2023-46042CRITICAL9.8An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinf...
CVE-2023-43251HIGH7.8XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this is...
CVE-2023-35187CRITICAL9.8The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerabil...
CVE-2023-35186HIGH8.8The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a...
CVE-2023-35185MEDIUM6.8The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM pri...
CVE-2023-35184CRITICAL9.8The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a...
CVE-2023-35183HIGH7.8The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows au...
CVE-2023-35182CRITICAL9.8The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now