2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28384HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-30380HIGH7.5An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal...
CVE-2023-1967CRITICAL9.8Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data...
CVE-2023-29489MEDIUM6.1An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ...
CVE-2023-29471MEDIUM5.5Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credent...
CVE-2023-25437HIGH8.8An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges an...
CVE-2023-29950MEDIUM5.5swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/...
CVE-2023-2355HIGH7.8Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deplo...
CVE-2023-28286MEDIUM6.1Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-28261MEDIUM5.7Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-27860MEDIUM5.3IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This informat...
CVE-2023-21712HIGH8.1Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-2335HIGH7.5 Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi...
CVE-2023-2158CRITICAL9.8Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain a...
CVE-2023-30852MEDIUM4.9Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-pro...
CVE-2023-30850HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerabili...
CVE-2023-30624HIGH8.8Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation o...
CVE-2023-30849HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerabili...
CVE-2023-30848HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API h...
CVE-2023-2350MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b...
CVE-2023-2349MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Service Provider Management System 1.0. Affec...
CVE-2023-30847HIGH8.2H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain ty...
CVE-2023-30338MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web...
CVE-2023-2348CRITICAL9.8A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been rated as critical. This ...
CVE-2023-2347CRITICAL9.8A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. Th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now