2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28473LOW3.3Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypa...
CVE-2023-28472MEDIUM5.3Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only ...
CVE-2023-28471MEDIUM5.4Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.
CVE-2023-30024MEDIUM6.6The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing u...
CVE-2023-2369CRITICAL9.8A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue aff...
CVE-2023-2368CRITICAL9.8A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been declared as critical. This vulner...
CVE-2023-2367CRITICAL9.8A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been classified as critical. This affe...
CVE-2023-2366CRITICAL9.8A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this i...
CVE-2023-2365CRITICAL9.8A vulnerability has been found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by t...
CVE-2023-2360HIGH7.5Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infras...
CVE-2023-30467CRITICAL9.8This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx...
CVE-2023-30466CRITICAL9.8This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx...
CVE-2023-2364MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Resort Reservation System 1.0. Affecte...
CVE-2023-2363CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This ...
CVE-2023-2361MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-28882HIGH7.5Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be...
CVE-2023-28528HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c...
CVE-2023-31436HIGH7.8qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can...
CVE-2023-27557HIGH7.5IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6...
CVE-2023-27556HIGH7.5IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02...
CVE-2023-2356HIGH7.5Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
CVE-2023-29169HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-29150HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-28716HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-28400HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now