2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25004HIGH7.8A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploi...
CVE-2023-23468MEDIUM5.5IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insuffic...
CVE-2023-22593HIGH7.8 IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to securit...
CVE-2023-34839MEDIUM6.8A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain priv...
CVE-2023-34838MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34837MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34836MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-34835MEDIUM5.4A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot...
CVE-2023-33567Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-33566Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-28857HIGH7.5Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authe...
CVE-2023-26276HIGH7.5IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly ...
CVE-2023-26274MEDIUM5.4 IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2023-26273MEDIUM4.3IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validatio...
CVE-2023-35800MEDIUM4.3Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution ...
CVE-2023-35799MEDIUM5.5Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SE...
CVE-2023-34830MEDIUM5.4i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter...
CVE-2023-34240CRITICAL9.8Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target f...
CVE-2023-34099MEDIUM5.3Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it wa...
CVE-2023-34098MEDIUM5.3Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configura...
CVE-2023-32339MEDIUM6.1IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2023-3432CRITICAL10Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
CVE-2023-3431MEDIUM5.3Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
CVE-2023-3405HIGH7.5Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonym...
CVE-2023-36002MEDIUM4.3A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now