2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31747HIGH7.8Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp...
CVE-2023-31726HIGH7.5AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive informat...
CVE-2023-28015MEDIUM5.3The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed log...
CVE-2023-30382HIGH7.3A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code an...
CVE-2023-1508CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automa...
CVE-2023-31860MEDIUM5.4Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.
CVE-2023-31752CRITICAL9.8SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/...
CVE-2023-31518MEDIUM5.5A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial o...
CVE-2023-31517HIGH7.5A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) v...
CVE-2023-2703HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management Sy...
CVE-2023-2702HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authe...
CVE-2023-23306CRITICAL9.8The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnre...
CVE-2023-23305CRITICAL9.8The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading...
CVE-2023-23304CRITICAL9.1The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head sect...
CVE-2023-23303CRITICAL9.8The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its...
CVE-2023-23302CRITICAL9.8The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its para...
CVE-2023-23301CRITICAL9.8The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not ex...
CVE-2023-23300CRITICAL9.8The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its para...
CVE-2023-23299HIGH7.5The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can ...
CVE-2023-23298CRITICAL9.8The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its ...
CVE-2023-1837HIGH8.8Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy...
CVE-2023-1209MEDIUM5.4Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbi...
CVE-2023-25474HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Csaba Kissi About Me 3000 widget plugin <= 2.2.6 versions.
CVE-2023-33617HIGH7.2An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/ad...
CVE-2023-33599MEDIUM6.1EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now