2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4681MEDIUM5.5NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4678MEDIUM5.5Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-41744HIGH7.8Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron...
CVE-2023-41743HIGH7.8Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A...
CVE-2023-41717MEDIUM5.5Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file downl...
CVE-2023-34392HIGH8.8 A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Gr...
CVE-2023-34391MEDIUM5.5Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software o...
CVE-2023-31175CRITICAL9.8 An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Con...
CVE-2023-31174MEDIUM6.5 A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configur...
CVE-2023-31173HIGH8.4Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Win...
CVE-2023-31172HIGH7.4 An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerat...
CVE-2023-31171MEDIUM6.5 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer...
CVE-2023-31170MEDIUM6.5 An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE...
CVE-2023-31169MEDIUM5.7 An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator ...
CVE-2023-31168MEDIUM6.5 An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE...
CVE-2023-31167HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering L...
CVE-2023-41742HIGH7.5Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agen...
CVE-2023-41642MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealG...
CVE-2023-41640HIGH8.8An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows ...
CVE-2023-41638HIGH8.8An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attack...
CVE-2023-41637CRITICAL9.8An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers...
CVE-2023-41636CRITICAL9.8A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to ...
CVE-2023-41635MEDIUM6.5A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 al...
CVE-2023-33835HIGH7.5IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th...
CVE-2023-33834MEDIUM5.3IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now