2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33781HIGH8.8An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.
CVE-2023-30400CRITICAL9.8An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network ...
CVE-2023-34409CRITICAL9.8In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does no...
CVE-2023-33684MEDIUM5.7Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19...
CVE-2023-33569HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=upda...
CVE-2023-33477MEDIUM6.5In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special pa...
CVE-2023-2961LOW3.3A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.
CVE-2023-2603HIGH7.8A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overf...
CVE-2023-2602LOW3.3A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use caus...
CVE-2023-2253MEDIUM6.5A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the m...
CVE-2023-2157MEDIUM5.5A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashin...
CVE-2023-29632CRITICAL9.8PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
CVE-2023-1621MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions startin...
CVE-2023-33977MEDIUM5.4Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo...
CVE-2023-33959HIGH8.8notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry...
CVE-2023-33958MEDIUM6.5notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry...
CVE-2023-33957MEDIUM5.7notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry...
CVE-2023-33653HIGH8.8Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerabil...
CVE-2023-33652HIGH8.8Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerabil...
CVE-2023-33651HIGH7.5An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Comme...
CVE-2023-32683MEDIUM5.4Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL c...
CVE-2023-32682MEDIUM5.4Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be pos...
CVE-2023-2801MEDIUM5.3Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple ...
CVE-2023-2183MEDIUM6.4Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available ...
CVE-2023-22833MEDIUM6.5Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now