2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34463HIGH8.1DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af...
CVE-2023-3113HIGH7.5An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) ser...
CVE-2023-35933HIGH7.5OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vu...
CVE-2023-35930MEDIUM5.3SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical applica...
CVE-2023-35170Rejected reason: This CVE is a duplicate of another CVE.
CVE-2023-34422MEDIUM6.5A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a...
CVE-2023-34421MEDIUM6.5A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically ...
CVE-2023-34420HIGH7.2A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted call...
CVE-2023-34418HIGH8.1A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to ...
CVE-2023-33404CRITICAL9.8An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net vers...
CVE-2023-33176MEDIUM6.5BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versio...
CVE-2023-2993MEDIUM6.3A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API ca...
CVE-2023-2992HIGH7.5An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which ca...
CVE-2023-2290MEDIUM6.7A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elev...
CVE-2023-27082MEDIUM4.8Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers t...
CVE-2023-36252HIGH8.8An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a...
CVE-2023-2005HIGH8.8Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugi...
CVE-2023-33580MEDIUM4.8Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f...
CVE-2023-29459MEDIUM6.1The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMo...
CVE-2023-28485MEDIUM5.4A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticate...
CVE-2023-36301HIGH7.5Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
CVE-2023-25307HIGH7.8nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
CVE-2023-25306HIGH7.5MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.
CVE-2023-30261CRITICAL9.8Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET ...
CVE-2023-29438MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now