2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40306MEDIUM6.1SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a maliciou...
CVE-2023-30995HIGH7.5IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restricti...
CVE-2023-24965MEDIUM5.3IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM...
CVE-2023-41318MEDIUM5.4matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected vers...
CVE-2023-32332MEDIUM5.4IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection...
CVE-2023-42268CRITICAL9.8Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/s...
CVE-2023-41578HIGH7.5Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection...
CVE-2023-41575MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 a...
CVE-2023-41338MEDIUM5.3Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properl...
CVE-2023-38736HIGH7.8IBM QRadar WinCollect Agent 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, is vulnerable to a local esca...
CVE-2023-4782HIGH7.8Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously craf...
CVE-2023-39712MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-28010MEDIUM5.3In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target fu...
CVE-2023-4843MEDIUM4.8Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busines...
CVE-2023-39322HIGH7.5QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing...
CVE-2023-39321HIGH7.5Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVE-2023-39320CRITICAL9.8The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the ...
CVE-2023-39319MEDIUM6.1The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" ...
CVE-2023-39318MEDIUM6.1The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <sc...
CVE-2023-39676MEDIUM6.1FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi...
CVE-2023-40924HIGH7.5SolarView Compact < 6.00 is vulnerable to Directory Traversal.
CVE-2023-39584HIGH7.5Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
CVE-2023-39076MEDIUM4.6Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (bui...
CVE-2023-4807HIGH7.8Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the inter...
CVE-2023-4777MEDIUM4.3 An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with g...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now