2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4005CRITICAL9.8Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
CVE-2023-35019HIGH8.8IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary c...
CVE-2023-35016MEDIUM6.5IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the syste...
CVE-2023-37219HIGH7.8 Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CVE-2023-37218HIGH7.5 Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-37217MEDIUM5.3 Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
CVE-2023-37216MEDIUM6.5 AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the dev...
CVE-2023-37215CRITICAL9.8 JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
CVE-2023-37214CRITICAL9.8 Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
CVE-2023-37213CRITICAL9.8 Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
CVE-2023-32227CRITICAL9.8 Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
CVE-2023-32226MEDIUM6.5 Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files fro...
CVE-2023-32225HIGH7.2 Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges m...
CVE-2023-36542HIGH8.8Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retriev...
CVE-2023-2314MEDIUM6.5Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass nav...
CVE-2023-2313HIGH8.8Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who...
CVE-2023-2311MEDIUM6.5Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to ...
CVE-2023-3598HIGH8.8Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially e...
CVE-2023-38988MEDIUM4.3An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbi...
CVE-2023-3488MEDIUM5.5Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stac...
CVE-2023-38685MEDIUM4.3Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-38684HIGH7.5Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-38498MEDIUM6.5Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-37906MEDIUM4.3Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-37904LOW3.1Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now