Skip to main content

Year archive

CVEs published in 2023

Archive summary

28,817 CVEs published in 2023 — 3,655 Critical, 9,772 High, 14,072 Medium, 1,313 Low, 5 Unrated.

CVE-2022-42435

Published Jan 4, 2023

IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request for…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44036

Published Jan 3, 2023

In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's posit…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36943

Published Jan 3, 2023

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32648

Published Jan 3, 2023

In disp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…

CVSS 6.4 · Medium

CVE-2022-32645

Published Jan 3, 2023

In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interacti…

CVSS 4.1 · Medium

CVE-2022-32644

Published Jan 3, 2023

In vow, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…

CVSS 6.4 · Medium

CVE-2022-32639

Published Jan 3, 2023

In watchdog, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User i…

CVSS 4.4 · Medium
Showing 28,651-28,675 of 28,817 CVEsPage 1147 of 1153