2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35179HIGH7.2 A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-f...
CVE-2023-40235MEDIUM6.5An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate pro...
CVE-2023-4275Rejected reason: It is invalid.
CVE-2023-40225HIGH7.2HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2...
CVE-2023-38333MEDIUM6.1Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
CVE-2023-40224MEDIUM6.1MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
CVE-2023-40014MEDIUM5.3OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to versio...
CVE-2023-39806CRITICAL9.8iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
CVE-2023-39805CRITICAL9.8iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
CVE-2023-37625MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or ...
CVE-2023-32565CRITICAL9.1An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource...
CVE-2023-32564CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could...
CVE-2023-32563CRITICAL9.8An unauthenticated attacker could achieve the code execution through a RemoteControl server.
CVE-2023-32562CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could...
CVE-2023-32561HIGH7.5A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact coul...
CVE-2023-32560CRITICAL9.8An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup...
CVE-2023-28129HIGH7.8DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM ...
CVE-2023-38034CRITICAL9.8A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Swi...
CVE-2023-35085CRITICAL9.8An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Mon...
CVE-2023-32567CRITICAL9.8Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
CVE-2023-32566CRITICAL9.1An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource...
CVE-2023-23342HIGH7.1If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumve...
CVE-2023-39966CRITICAL9.81Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr...
CVE-2023-39965MEDIUM4.31Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attack...
CVE-2023-39964HIGH7.51Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now