2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31747 | HIGH | 7.8 | 1.2% | May 23, 2023 | Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp... |
| CVE-2023-31726 | HIGH | 7.5 | 1.1% | May 23, 2023 | AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive informat... |
| CVE-2023-28015 | MEDIUM | 5.3 | 0.4% | May 23, 2023 | The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed log... |
| CVE-2023-30382 | HIGH | 7.3 | 0.2% | May 23, 2023 | A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code an... |
| CVE-2023-1508 | CRITICAL | 9.8 | 0.6% | May 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automa... |
| CVE-2023-31860 | MEDIUM | 5.4 | 0.4% | May 23, 2023 | Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. |
| CVE-2023-31752 | CRITICAL | 9.8 | 0.8% | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/... |
| CVE-2023-31518 | MEDIUM | 5.5 | 0.3% | May 23, 2023 | A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial o... |
| CVE-2023-31517 | HIGH | 7.5 | 0.9% | May 23, 2023 | A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2023-2703 | HIGH | 7.5 | 0.6% | May 23, 2023 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management Sy... |
| CVE-2023-2702 | HIGH | 8.8 | 0.7% | May 23, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authe... |
| CVE-2023-23306 | CRITICAL | 9.8 | 1.2% | May 23, 2023 | The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnre... |
| CVE-2023-23305 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading... |
| CVE-2023-23304 | CRITICAL | 9.1 | 0.6% | May 23, 2023 | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head sect... |
| CVE-2023-23303 | CRITICAL | 9.8 | 0.8% | May 23, 2023 | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its... |
| CVE-2023-23302 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its para... |
| CVE-2023-23301 | CRITICAL | 9.8 | 1.1% | May 23, 2023 | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not ex... |
| CVE-2023-23300 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its para... |
| CVE-2023-23299 | HIGH | 7.5 | 0.8% | May 23, 2023 | The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can ... |
| CVE-2023-23298 | CRITICAL | 9.8 | 1.5% | May 23, 2023 | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its ... |
| CVE-2023-1837 | HIGH | 8.8 | 0.5% | May 23, 2023 | Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy... |
| CVE-2023-1209 | MEDIUM | 5.4 | 0.4% | May 23, 2023 | Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbi... |
| CVE-2023-25474 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Csaba Kissi About Me 3000 widget plugin <= 2.2.6 versions. |
| CVE-2023-33617 | HIGH | 7.2 | 5.2% | May 23, 2023 | An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/ad... |
| CVE-2023-33599 | MEDIUM | 6.1 | 0.4% | May 23, 2023 | EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now