2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34625HIGH8.1ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mech...
CVE-2023-31753CRITICAL9.8SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via th...
CVE-2023-30200HIGH7.5In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Adv...
CVE-2023-3792MEDIUM6.5A vulnerability was found in Beijing Netcon NS-ASG 6.3. It has been classified as problematic. This affects an unknown p...
CVE-2023-38617MEDIUM6.1Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerabilit...
CVE-2023-38523MEDIUM5.3The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, with...
CVE-2023-37602MEDIUM6.1An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers t...
CVE-2023-37601HIGH7.5Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the componen...
CVE-2023-37600MEDIUM6.1Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerabilit...
CVE-2023-37165CRITICAL9.8Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_po...
CVE-2023-37164MEDIUM6.1Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=sho...
CVE-2023-3791CRITICAL9.8A vulnerability was found in IBOS OA 4.5.5 and classified as critical. Affected by this issue is the function actionExpo...
CVE-2023-38335MEDIUM5.3Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" ...
CVE-2023-38334MEDIUM6.5Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omn...
CVE-2023-37728MEDIUM6.1IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-31462HIGH8.8An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writa...
CVE-2023-31461HIGH7.5Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed au...
CVE-2023-3790MEDIUM5.4A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the fu...
CVE-2023-37471CRITICAL9.8Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Feder...
CVE-2023-3789MEDIUM6.1A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown functio...
CVE-2023-3788MEDIUM5.4A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This iss...
CVE-2023-38203CRITICAL9.8Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deseria...
CVE-2023-3787MEDIUM5.4A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects u...
CVE-2023-3347MEDIUM5.9A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin ...
CVE-2023-34968MEDIUM5.3A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now