2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42805HIGH7.5quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QU...
CVE-2023-42458MEDIUM5.4Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin...
CVE-2023-34577CRITICAL9.8SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary ...
CVE-2023-42456HIGH8.1Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att...
CVE-2023-42457HIGH7.5plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and ...
CVE-2023-41048MEDIUM5.4plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten...
CVE-2023-40183MEDIUM5.3DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability ...
CVE-2023-43637HIGH7.8 Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the las...
CVE-2023-43634HIGH8.8 When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous proje...
CVE-2023-43633HIGH8.8 On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the f...
CVE-2023-43632CRITICAL9.9 As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limi...
CVE-2023-43631HIGH8.8 On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is pr...
CVE-2023-43309MEDIUM4.8There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input ...
CVE-2023-43274HIGH7.5Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
CVE-2023-43242CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.
CVE-2023-43241CRITICAL9.8D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioS...
CVE-2023-43240CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.
CVE-2023-43239CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.
CVE-2023-43238CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.
CVE-2023-43237CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.
CVE-2023-43236CRITICAL9.8D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWan...
CVE-2023-43235CRITICAL9.8D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownS...
CVE-2023-4753MEDIUM5.5OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the err...
CVE-2023-5104MEDIUM6.5Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.
CVE-2023-4760CRITICAL9.8In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now