2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39970CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code ...
CVE-2023-40315HIGH8In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FIL...
CVE-2023-40168MEDIUM6.5TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to ver...
CVE-2023-36847MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthe...
CVE-2023-36846MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth...
CVE-2023-36845CRITICAL9.8A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series ...
CVE-2023-36844MEDIUM5.3A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthen...
CVE-2023-36106HIGH7.5An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive info...
CVE-2023-31946HIGH7.2File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2023-31945HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31944HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31943HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31942MEDIUM4.8Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitr...
CVE-2023-31941HIGH7.2File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2023-31940HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31939HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31938HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-40313HIGH8.8A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridi...
CVE-2023-39743MEDIUM5.3lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
CVE-2023-39741MEDIUM5.5lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/l...
CVE-2023-38905MEDIUM5.5SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via th...
CVE-2023-38843HIGH8An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the descri...
CVE-2023-26469CRITICAL9.8In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
CVE-2023-40165HIGH7.5rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici...
CVE-2023-37914HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now