2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35179 | HIGH | 7.2 | 0.9% | Aug 11, 2023 | A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-f... |
| CVE-2023-40235 | MEDIUM | 6.5 | 0.7% | Aug 10, 2023 | An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate pro... |
| CVE-2023-4275 | — | — | — | Aug 10, 2023 | Rejected reason: It is invalid. |
| CVE-2023-40225 | HIGH | 7.2 | 1.8% | Aug 10, 2023 | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2... |
| CVE-2023-38333 | MEDIUM | 6.1 | 2.0% | Aug 10, 2023 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. |
| CVE-2023-40224 | MEDIUM | 6.1 | 0.4% | Aug 10, 2023 | MISP 2.4.174 allows XSS in app/View/Events/index.ctp. |
| CVE-2023-40014 | MEDIUM | 5.3 | 0.6% | Aug 10, 2023 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to versio... |
| CVE-2023-39806 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. |
| CVE-2023-39805 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. |
| CVE-2023-37625 | MEDIUM | 5.4 | 0.6% | Aug 10, 2023 | A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or ... |
| CVE-2023-32565 | CRITICAL | 9.1 | 2.0% | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2023-32564 | CRITICAL | 9.8 | 37.4% | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could... |
| CVE-2023-32563 | CRITICAL | 9.8 | 90.2% | Aug 10, 2023 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. |
| CVE-2023-32562 | CRITICAL | 9.8 | 38.4% | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could... |
| CVE-2023-32561 | HIGH | 7.5 | 2.2% | Aug 10, 2023 | A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact coul... |
| CVE-2023-32560 | CRITICAL | 9.8 | 98.9% | Aug 10, 2023 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup... |
| CVE-2023-28129 | HIGH | 7.8 | 0.3% | Aug 10, 2023 | DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM ... |
| CVE-2023-38034 | CRITICAL | 9.8 | 1.0% | Aug 10, 2023 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Swi... |
| CVE-2023-35085 | CRITICAL | 9.8 | 0.7% | Aug 10, 2023 | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Mon... |
| CVE-2023-32567 | CRITICAL | 9.8 | 2.1% | Aug 10, 2023 | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 |
| CVE-2023-32566 | CRITICAL | 9.1 | 2.1% | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2023-23342 | HIGH | 7.1 | 0.2% | Aug 10, 2023 | If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumve... |
| CVE-2023-39966 | CRITICAL | 9.8 | 0.7% | Aug 10, 2023 | 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr... |
| CVE-2023-39965 | MEDIUM | 4.3 | 0.4% | Aug 10, 2023 | 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attack... |
| CVE-2023-39964 | HIGH | 7.5 | 0.8% | Aug 10, 2023 | 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now