2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3173CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
CVE-2023-3172HIGH7.2Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
CVE-2023-34112HIGH8.8JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/java...
CVE-2023-34243MEDIUM5.3TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgst...
CVE-2023-34233HIGH8.8The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2023-34232HIGH8.8snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) b...
CVE-2023-34230HIGH8.8snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 vi...
CVE-2023-32751MEDIUM5.4Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera...
CVE-2023-32750MEDIUM6.5Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which ...
CVE-2023-29405CRITICAL9.8The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici...
CVE-2023-29404CRITICAL9.8The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici...
CVE-2023-29403HIGH7.8On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can...
CVE-2023-29402CRITICAL9.8The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when ru...
CVE-2023-29401MEDIUM4.3The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename ...
CVE-2023-24535HIGH7.5Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minu...
CVE-2023-0954CRITICAL9.8A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentia...
CVE-2023-34231HIGH8.8gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snow...
CVE-2023-32749HIGH8.8Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t...
CVE-2023-34962HIGH8.1Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another stu...
CVE-2023-34961MEDIUM6.1Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/co...
CVE-2023-34959MEDIUM5.3An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain i...
CVE-2023-34958MEDIUM4.3Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download docum...
CVE-2023-34096HIGH8.8Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends....
CVE-2023-3165MEDIUM6.1A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. A...
CVE-2023-34571MEDIUM6.7Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /gofo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now