2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3462MEDIUM5.3HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker m...
CVE-2023-39122CRITICAL9.8BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This i...
CVE-2023-3983HIGH8.8An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authentic...
CVE-2023-38989MEDIUM4.3An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrar...
CVE-2023-4026Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-4024. Reason: This record is a duplicate ...
CVE-2023-4010Rejected reason: Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function...
CVE-2023-4004HIGH7.8A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove functio...
CVE-2023-3997HIGH7.8Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s t...
CVE-2023-3817MEDIUM5.3Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use ...
CVE-2023-38750HIGH7.5In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and ...
CVE-2023-37771CRITICAL9.8Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
CVE-2023-37580MEDIUM6.1Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVE-2023-34917MEDIUM6.1Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
CVE-2023-34916MEDIUM6.1Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
CVE-2023-38311MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System ...
CVE-2023-38310MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configu...
CVE-2023-38309MEDIUM6.1An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the pack...
CVE-2023-38308MEDIUM6.1An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel fu...
CVE-2023-38307MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a...
CVE-2023-38306MEDIUM6.1An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file up...
CVE-2023-38305MEDIUM6.1An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting...
CVE-2023-38304MEDIUM5.4An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a...
CVE-2023-38303MEDIUM5.4An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Co...
CVE-2023-35792MEDIUM6.1Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS).
CVE-2023-35791MEDIUM6.1Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now