2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4052MEDIUM6.5The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d...
CVE-2023-4051HIGH7.5A website could have obscured the full screen notification by using the file open dialog. This could have led to user co...
CVE-2023-4050HIGH7.5In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a pote...
CVE-2023-4049MEDIUM5.9Race conditions in reference counting code were found through code inspection. These could have resulted in potentially ...
CVE-2023-4048HIGH7.5An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. ...
CVE-2023-4047HIGH8.8A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting...
CVE-2023-4046MEDIUM5.3In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in i...
CVE-2023-4045MEDIUM5.3Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from anot...
CVE-2023-38357MEDIUM5.3Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a...
CVE-2023-39110HIGH8.8rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPa...
CVE-2023-39109HIGH8.8rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Fun...
CVE-2023-39108HIGH8.8rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Fun...
CVE-2023-34634HIGH7.8Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green...
CVE-2023-31710CRITICAL9.8TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow...
CVE-2023-37478CRITICAL9.8pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry ...
CVE-2023-32302Rejected reason: Authoritative user requested CVE rejection https://github.com/github/advisory-database/pull/2575#issue...
CVE-2023-23548MEDIUM6.1Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
CVE-2023-26139HIGH7.5Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of th...
CVE-2023-36984HIGH7.5LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36983HIGH7.5LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-34960CRITICAL9.8A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex...
CVE-2023-4033HIGH7.8OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
CVE-2023-37772HIGH8.8Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /...
CVE-2023-37496MEDIUM5.4HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a vi...
CVE-2023-3825HIGH7.5 PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now