2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29681MEDIUM5.7Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker ...
CVE-2023-29680MEDIUM5.7Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attac...
CVE-2023-27108MEDIUM5.3An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns t...
CVE-2023-27035HIGH7.5An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio an...
CVE-2023-26987MEDIUM6.5An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via craf...
CVE-2023-2197LOW2.5HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction...
CVE-2023-22924MEDIUM4.9A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot...
CVE-2023-22923MEDIUM6.5A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could all...
CVE-2023-22922HIGH7.5A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot...
CVE-2023-22921HIGH7.5A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could al...
CVE-2023-22919HIGH8.8The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allo...
CVE-2023-22503MEDIUM5.3Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of a...
CVE-2023-2451CRITICAL9.8A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affec...
CVE-2023-29643MEDIUM5.4Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post fu...
CVE-2023-29641MEDIUM6.1Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script ...
CVE-2023-29639MEDIUM5.4Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-29638MEDIUM5.4Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, ...
CVE-2023-29637MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-29636MEDIUM5.4Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ...
CVE-2023-29635CRITICAL9.8File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file...
CVE-2023-28092MEDIUM6.8A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could resul...
CVE-2023-25492HIGH8.8A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined ...
CVE-2023-0683HIGH8.8A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API ca...
CVE-2023-30859CRITICAL9.8Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload...
CVE-2023-30063HIGH7.5D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now