2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4563Rejected reason: This was assigned as a duplicate of CVE-2023-4244.
CVE-2023-41588MEDIUM6.1A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scri...
CVE-2023-37755CRITICAL9.8i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and...
CVE-2023-37739MEDIUM6.5i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
CVE-2023-32665MEDIUM5.5A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant...
CVE-2023-32643HIGH7.8A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fi...
CVE-2023-32636HIGH7.5A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by add...
CVE-2023-32611MEDIUM5.5A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause ...
CVE-2023-29499HIGH7.5A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, lea...
CVE-2023-4766CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL I...
CVE-2023-4669CRITICAL9.8Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. Th...
CVE-2023-41011CRITICAL9.8Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a...
CVE-2023-39286MEDIUM4.3A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an un...
CVE-2023-39285MEDIUM4.3A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an un...
CVE-2023-4832CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Mana...
CVE-2023-41010MEDIUM5.5Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.T...
CVE-2023-40779MEDIUM6.1An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafte...
CVE-2023-1576Rejected reason: This is a duplicate of an earlier CVE, CVE-2022-47069.
CVE-2023-4951MEDIUM4.8A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Conf...
CVE-2023-36250HIGH7.8CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via cr...
CVE-2023-42180HIGH8.8An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute htm...
CVE-2023-42178MEDIUM6.5Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.
CVE-2023-30909CRITICAL9.8A remote authentication bypass issue exists in some OneView APIs.
CVE-2023-1108HIGH7.5A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake sta...
CVE-2023-2848HIGH8.8Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now