2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-49115HIGH7.5 MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u...
CVE-2023-47867HIGH8.8 MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect...
CVE-2023-36496HIGH8.8Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their...
CVE-2023-47257HIGH8.1ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted...
CVE-2023-51446HIGH8.1GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication ...
CVE-2023-51939HIGH8.8An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker...
CVE-2023-28807HIGH7.5In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables...
CVE-2023-50165HIGH8.6Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
CVE-2023-6779HIGH7.5An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This functio...
CVE-2023-6246HIGH7.8A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called ...
CVE-2023-44313HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive se...
CVE-2023-44312HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa...
CVE-2023-31505HIGH7.2An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrar...
CVE-2023-5389HIGH7.5 An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ...
CVE-2023-6258HIGH8.1A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography St...
CVE-2023-46231HIGH7.2In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when...
CVE-2023-37518HIGH8.8HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary...
CVE-2023-6942HIGH7.5Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5...
CVE-2023-6374HIGH7.5Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 ...
CVE-2023-36260HIGH7.5An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of servi...
CVE-2023-5372HIGH7.2The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and N...
CVE-2023-51843HIGH8.2react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.
CVE-2023-4552HIGH7.1Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenti...
CVE-2023-4551HIGH8.8Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBu...
CVE-2023-4550HIGH7.5Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now