2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35069HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Tra...
CVE-2023-2957CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Flor...
CVE-2023-1547CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik all...
CVE-2023-37565HIGH8Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute ...
CVE-2023-37564HIGH8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to ex...
CVE-2023-3444MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions sta...
CVE-2023-3424HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions sta...
CVE-2023-3363LOW3.8An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16...
CVE-2023-3362MEDIUM5.3An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 all...
CVE-2023-3343HIGH8.8The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1...
CVE-2023-3342CRITICAL9.9The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and...
CVE-2023-38199CRITICAL9.8coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on...
CVE-2023-38198CRITICAL9.8acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
CVE-2023-37563MEDIUM6.5ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthoriz...
CVE-2023-37562HIGH8.8Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 an...
CVE-2023-34137CRITICAL9.8SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks lead...
CVE-2023-34136CRITICAL9.8Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location no...
CVE-2023-34135MEDIUM6.5Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary fil...
CVE-2023-34134MEDIUM6.5Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authentic...
CVE-2023-34133HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and ...
CVE-2023-34132CRITICAL9.8Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the...
CVE-2023-34131MEDIUM5.3Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unaut...
CVE-2023-2620LOW3.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions f...
CVE-2023-2576MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions sta...
CVE-2023-2200MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions sta...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now