2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26442LOW3.2In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by th...
CVE-2023-26441MEDIUM5.5Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when access...
CVE-2023-26440HIGH7.8The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized ...
CVE-2023-26439HIGH7.8The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before gett...
CVE-2023-26438LOW3.1External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, inv...
CVE-2023-26430MEDIUM4.3Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be...
CVE-2023-3426MEDIUM4.3The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not...
CVE-2023-4067MEDIUM6.1The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2023-3401MEDIUM6.5An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1...
CVE-2023-2022MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 1...
CVE-2023-38556HIGH7.5Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the pri...
CVE-2023-4011HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to ...
CVE-2023-4016LOW3.3Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability t...
CVE-2023-3994HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starti...
CVE-2023-3993HIGH7.5An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting...
CVE-2023-3900HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions start...
CVE-2023-3500MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions start...
CVE-2023-31927MEDIUM5.3An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c...
CVE-2023-31926HIGH7.1System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2....
CVE-2023-3385MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting fr...
CVE-2023-3364HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions start...
CVE-2023-38990MEDIUM4.3An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrar...
CVE-2023-36121MEDIUM5.4Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the descriptio...
CVE-2023-31928MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS v...
CVE-2023-31432HIGH7.8Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now