2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29681 | MEDIUM | 5.7 | 0.4% | May 1, 2023 | Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker ... |
| CVE-2023-29680 | MEDIUM | 5.7 | 0.4% | May 1, 2023 | Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attac... |
| CVE-2023-27108 | MEDIUM | 5.3 | 0.6% | May 1, 2023 | An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns t... |
| CVE-2023-27035 | HIGH | 7.5 | 1.8% | May 1, 2023 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio an... |
| CVE-2023-26987 | MEDIUM | 6.5 | 1.1% | May 1, 2023 | An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via craf... |
| CVE-2023-2197 | LOW | 2.5 | 0.1% | May 1, 2023 | HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction... |
| CVE-2023-22924 | MEDIUM | 4.9 | 0.8% | May 1, 2023 | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot... |
| CVE-2023-22923 | MEDIUM | 6.5 | 0.8% | May 1, 2023 | A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could all... |
| CVE-2023-22922 | HIGH | 7.5 | 0.9% | May 1, 2023 | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot... |
| CVE-2023-22921 | HIGH | 7.5 | 0.5% | May 1, 2023 | A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could al... |
| CVE-2023-22919 | HIGH | 8.8 | 1.6% | May 1, 2023 | The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allo... |
| CVE-2023-22503 | MEDIUM | 5.3 | 0.8% | May 1, 2023 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of a... |
| CVE-2023-2451 | CRITICAL | 9.8 | 0.7% | May 1, 2023 | A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affec... |
| CVE-2023-29643 | MEDIUM | 5.4 | 0.5% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post fu... |
| CVE-2023-29641 | MEDIUM | 6.1 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script ... |
| CVE-2023-29639 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-29638 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, ... |
| CVE-2023-29637 | MEDIUM | 6.1 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-29636 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-29635 | CRITICAL | 9.8 | 1.1% | May 1, 2023 | File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file... |
| CVE-2023-28092 | MEDIUM | 6.8 | 0.2% | May 1, 2023 | A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could resul... |
| CVE-2023-25492 | HIGH | 8.8 | 0.5% | May 1, 2023 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined ... |
| CVE-2023-0683 | HIGH | 8.8 | 0.6% | May 1, 2023 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API ca... |
| CVE-2023-30859 | CRITICAL | 9.8 | 1.1% | May 1, 2023 | Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload... |
| CVE-2023-30063 | HIGH | 7.5 | 1.1% | May 1, 2023 | D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now