2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35813CRITICAL9.8Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi...
CVE-2023-35811HIGH8.8An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been...
CVE-2023-35810HIGH7.2An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection...
CVE-2023-35809HIGH8.8An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability h...
CVE-2023-35808HIGH8.8An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnera...
CVE-2023-3295HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl...
CVE-2023-28295HIGH7.8Microsoft Publisher Remote Code Execution Vulnerability
CVE-2023-28287HIGH7.8Microsoft Publisher Remote Code Execution Vulnerability
CVE-2023-34459MEDIUM5.9OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2...
CVE-2023-35790HIGH7.5An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can le...
CVE-2023-35789MEDIUM5.5An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only ...
CVE-2023-35788HIGH7.8An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an ou...
CVE-2023-33438MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to injec...
CVE-2023-30905HIGH7.8The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced ...
CVE-2023-30904MEDIUM5.5A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information...
CVE-2023-30903MEDIUM5.5HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6...
CVE-2023-3195MEDIUM5.5A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the ...
CVE-2023-35784CRITICAL9.8A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, ...
CVE-2023-34475MEDIUM5.5A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attac...
CVE-2023-34474MEDIUM5.5A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A loca...
CVE-2023-25187HIGH7An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures...
CVE-2023-3268HIGH7.1An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c i...
CVE-2023-25645HIGH7.7There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, ...
CVE-2023-25188HIGH7.8An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) remo...
CVE-2023-25186LOW2.8An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) remo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now