2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-53970HIGH8.7Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass aut...
CVE-2023-53965HIGH7.8SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to ...
CVE-2023-53962HIGH8.8SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote atta...
CVE-2023-25446HIGH7.7Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured...
CVE-2023-53958HIGH8.6LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT...
CVE-2023-53957HIGH8.8Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malic...
CVE-2023-53956HIGH8.8Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr...
CVE-2023-53954HIGH8.5ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privile...
CVE-2023-53952HIGH8.8Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P...
CVE-2023-53949HIGH8.5AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the P...
CVE-2023-53947HIGH8.5OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile...
CVE-2023-53946HIGH8.5Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow...
CVE-2023-53945HIGH8.8BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitra...
CVE-2023-53944HIGH7.1EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access fi...
CVE-2023-53940HIGH8.4Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma...
CVE-2023-53937HIGH8.5Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 ...
CVE-2023-53934HIGH8.7A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requ...
CVE-2023-53933HIGH8.8Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious...
CVE-2023-53930HIGH7.5ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to do...
CVE-2023-53929HIGH8phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into...
CVE-2023-53924HIGH8.8UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo...
CVE-2023-53917HIGH8.7Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad...
CVE-2023-53913HIGH8.8Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in...
CVE-2023-53912HIGH8.5USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow...
CVE-2023-53908HIGH8.8HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now