2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39970 | CRITICAL | 9.8 | 0.9% | Aug 17, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code ... |
| CVE-2023-40315 | HIGH | 8 | 2.5% | Aug 17, 2023 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FIL... |
| CVE-2023-40168 | MEDIUM | 6.5 | 0.6% | Aug 17, 2023 | TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to ver... |
| CVE-2023-36847 | MEDIUM | 5.3 | 84.7% | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthe... |
| CVE-2023-36846 | MEDIUM | 5.3 | 94.2% | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth... |
| CVE-2023-36845 | CRITICAL | 9.8 | 93.5% | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series ... |
| CVE-2023-36844 | MEDIUM | 5.3 | 89.6% | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthen... |
| CVE-2023-36106 | HIGH | 7.5 | 0.7% | Aug 17, 2023 | An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive info... |
| CVE-2023-31946 | HIGH | 7.2 | 1.2% | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-31945 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31944 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31943 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31942 | MEDIUM | 4.8 | 0.6% | Aug 17, 2023 | Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitr... |
| CVE-2023-31941 | HIGH | 7.2 | 1.2% | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-31940 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31939 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31938 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-40313 | HIGH | 8.8 | 0.7% | Aug 17, 2023 | A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridi... |
| CVE-2023-39743 | MEDIUM | 5.3 | 0.7% | Aug 17, 2023 | lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c. |
| CVE-2023-39741 | MEDIUM | 5.5 | 0.3% | Aug 17, 2023 | lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/l... |
| CVE-2023-38905 | MEDIUM | 5.5 | 0.3% | Aug 17, 2023 | SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via th... |
| CVE-2023-38843 | HIGH | 8 | 0.7% | Aug 17, 2023 | An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the descri... |
| CVE-2023-26469 | CRITICAL | 9.8 | 81.9% | Aug 17, 2023 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. |
| CVE-2023-40165 | HIGH | 7.5 | 0.4% | Aug 17, 2023 | rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici... |
| CVE-2023-37914 | HIGH | 8.8 | 1.5% | Aug 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now