2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45909MEDIUM6.1zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
CVE-2023-37502HIGH8.8HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that c...
CVE-2023-45958MEDIUM6.1Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pa...
CVE-2023-45814MEDIUM5.3Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So...
CVE-2023-45812HIGH7.5The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that us...
CVE-2023-45146CRITICAL10XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework ...
CVE-2023-43801HIGH7.1Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/...
CVE-2023-43800HIGH7.8Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/t...
CVE-2023-45813HIGH7.5Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_lin...
CVE-2023-45145LOW3.6Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusti...
CVE-2023-43803HIGH7.1Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/...
CVE-2023-43802HIGH7.8Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` ...
CVE-2023-4601CRITICAL9.8A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosur...
CVE-2023-35663HIGH7.5 In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul...
CVE-2023-35656HIGH7.5 In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c...
CVE-2023-26300HIGH7.8A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow e...
CVE-2023-45912HIGH7.5WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers ...
CVE-2023-45911CRITICAL9.8An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user wi...
CVE-2023-30911HIGH7.5HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service.
CVE-2023-20261MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve...
CVE-2023-5642CRITICAL9.8Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, whi...
CVE-2023-46009HIGH7.8gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
CVE-2023-45383HIGH7.5In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest c...
CVE-2023-43250HIGH7.8XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attacker...
CVE-2023-5631MEDIUM5.4Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now