2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2903MEDIUM6.5A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an u...
CVE-2023-31147MEDIUM6.5c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to g...
CVE-2023-31130MEDIUM6.4c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 ad...
CVE-2023-31124LOW3.7c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RAND...
CVE-2023-2902MEDIUM6.5A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by th...
CVE-2023-2901MEDIUM6.5A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by...
CVE-2023-2804MEDIUM6.5A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrge...
CVE-2023-2900HIGH7.5A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected ...
CVE-2023-33280CRITICAL9.8In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be execut...
CVE-2023-33279CRITICAL9.8In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed w...
CVE-2023-33278CRITICAL9.8In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a...
CVE-2023-33263HIGH7.5In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WF...
CVE-2023-2255MEDIUM5.3Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a docum...
CVE-2023-25439MEDIUM6.1Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr...
CVE-2023-0950HIGH7.8Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice all...
CVE-2023-26216HIGH7.2The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an att...
CVE-2023-26215MEDIUM6.5The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with lo...
CVE-2023-30851MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users...
CVE-2023-30615MEDIUM5.4Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations....
CVE-2023-33751MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H...
CVE-2023-33750MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H...
CVE-2023-32694MEDIUM5.4Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing ...
CVE-2023-33356MEDIUM5.4IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33355HIGH7.5IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitiv...
CVE-2023-2851CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now