2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40376MEDIUM6.5IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou...
CVE-2023-27433HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery...
CVE-2023-25025HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ...
CVE-2023-22515CRITICAL9.8Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited...
CVE-2023-1832HIGH8.1An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant...
CVE-2023-5373CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected i...
CVE-2023-4497MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4496MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4495MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4494CRITICAL9.8Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long us...
CVE-2023-4493MEDIUM5.4Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects m...
CVE-2023-4492MEDIUM6.1Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, mid...
CVE-2023-4491CRITICAL9.8Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could ...
CVE-2023-4090MEDIUM6.1Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tag...
CVE-2023-4037MEDIUM5.5Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local a...
CVE-2023-44208CRITICAL9.1Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr...
CVE-2023-43261HIGH7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti...
CVE-2023-3361HIGH7.5A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as...
CVE-2023-3153MEDIUM5.3A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al...
CVE-2023-3038HIGH7.5SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote atta...
CVE-2023-3037HIGH8.6Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a re...
CVE-2023-22618HIGH7.8If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users ...
CVE-2023-4997HIGH8.8Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to cha...
CVE-2023-4586HIGH7.4A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna...
CVE-2023-3701HIGH8.8Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now