2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42657CRITICAL9.6 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker ...
CVE-2023-42487HIGH7.5Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42486HIGH7.8Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
CVE-2023-42462CRITICAL9.1GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-42461CRITICAL9.8GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-42460HIGH7.5Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is...
CVE-2023-42453MEDIUM4.3Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forg...
CVE-2023-41996MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6. Apps that fail verification che...
CVE-2023-41995HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS...
CVE-2023-41986MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may b...
CVE-2023-41984HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ...
CVE-2023-41981MEDIUM4.4The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ...
CVE-2023-41980MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom...
CVE-2023-41979MEDIUM4.7A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modi...
CVE-2023-41968MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS...
CVE-2023-41962MEDIUM6.1Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows...
CVE-2023-41904MEDIUM5.4Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
CVE-2023-41888MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41878CRITICAL9.8MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface t...
CVE-2023-41861MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions.
CVE-2023-41860MEDIUM6.1Unauth. Cross-Site Scripting (XSS) vulnerability in TravelMap plugin <= 1.0.1 versions.
CVE-2023-41653MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
CVE-2023-41335LOW3.7Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their...
CVE-2023-41333HIGH8.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability ...
CVE-2023-41332LOW3.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In Cilium clusters where Cili...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now