2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39001CRITICAL9.8A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Busines...
CVE-2023-39000MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Ed...
CVE-2023-38999MEDIUM6.5A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and ...
CVE-2023-38998MEDIUM6.1An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows a...
CVE-2023-38997HIGH7.2A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Busine...
CVE-2023-23346HIGH7.1HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise t...
CVE-2023-39531MEDIUM6.8Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2,...
CVE-2023-40012HIGH7.5uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthen...
CVE-2023-3518HIGH7.3HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access rega...
CVE-2023-39969CRITICAL9.8uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of ...
CVE-2023-4273MEDIUM6.7A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file nam...
CVE-2023-3953MEDIUM5.3 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could caus...
CVE-2023-34545CRITICAL9.8A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or t...
CVE-2023-33953HIGH7.5gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clien...
CVE-2023-32782HIGH7.2A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authent...
CVE-2023-32781HIGH7.2A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au...
CVE-2023-31452HIGH8.8A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows re...
CVE-2023-31450MEDIUM4.7A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an a...
CVE-2023-31449MEDIUM4.7A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where a...
CVE-2023-31448MEDIUM4.7A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authe...
CVE-2023-24015MEDIUM4.3A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forc...
CVE-2023-23903MEDIUM4.9An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not chec...
CVE-2023-3632CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App al...
CVE-2023-38213MEDIUM5.5Adobe Dimension version 3.4.9 is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensit...
CVE-2023-38212HIGH7.8Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now