2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-50437HIGH8.6An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/defau...
CVE-2023-38372HIGH7.5An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to imp...
CVE-2023-34198HIGH7.3In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 th...
CVE-2023-25926HIGH8.2IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Inje...
CVE-2023-25921HIGH8.8 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer f...
CVE-2023-49338HIGH7.5Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals end...
CVE-2023-45859HIGH7.6In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through...
CVE-2023-25925HIGH8.8IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker ...
CVE-2023-25922HIGH8.8IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer fi...
CVE-2023-52047HIGH8.8Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
CVE-2023-52226HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a thro...
CVE-2023-52223HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects Ma...
CVE-2023-51683HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects...
CVE-2023-51747HIGH7.1Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h...
CVE-2023-7016HIGH7.8A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST...
CVE-2023-5993HIGH7.8A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker ...
CVE-2023-7165HIGH7.5The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive d...
CVE-2023-6585HIGH7.5The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated...
CVE-2023-6584HIGH7.5The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only kno...
CVE-2023-50379HIGH8.8Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fi...
CVE-2023-36237HIGH8.8Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a cr...
CVE-2023-52474HIGH7.8In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iove...
CVE-2023-52469HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_po...
CVE-2023-52468HIGH7.8In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The ...
CVE-2023-49960HIGH7.5In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmwa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now