2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28384 | HIGH | 8.8 | 44.8% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-30380 | HIGH | 7.5 | 1.2% | Apr 27, 2023 | An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal... |
| CVE-2023-1967 | CRITICAL | 9.8 | 0.8% | Apr 27, 2023 | Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data... |
| CVE-2023-29489 | MEDIUM | 6.1 | 65.5% | Apr 27, 2023 | An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ... |
| CVE-2023-29471 | MEDIUM | 5.5 | 0.2% | Apr 27, 2023 | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credent... |
| CVE-2023-25437 | HIGH | 8.8 | 14.1% | Apr 27, 2023 | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges an... |
| CVE-2023-29950 | MEDIUM | 5.5 | 0.3% | Apr 27, 2023 | swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/... |
| CVE-2023-2355 | HIGH | 7.8 | 0.2% | Apr 27, 2023 | Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deplo... |
| CVE-2023-28286 | MEDIUM | 6.1 | 0.6% | Apr 27, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-28261 | MEDIUM | 5.7 | 0.6% | Apr 27, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-27860 | MEDIUM | 5.3 | 0.5% | Apr 27, 2023 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This informat... |
| CVE-2023-21712 | HIGH | 8.1 | 1.0% | Apr 27, 2023 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-2335 | HIGH | 7.5 | 0.3% | Apr 27, 2023 | Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi... |
| CVE-2023-2158 | CRITICAL | 9.8 | 0.6% | Apr 27, 2023 | Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain a... |
| CVE-2023-30852 | MEDIUM | 4.9 | 0.8% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-pro... |
| CVE-2023-30850 | HIGH | 8.8 | 0.8% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerabili... |
| CVE-2023-30624 | HIGH | 8.8 | 0.4% | Apr 27, 2023 | Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation o... |
| CVE-2023-30849 | HIGH | 8.8 | 0.8% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerabili... |
| CVE-2023-30848 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API h... |
| CVE-2023-2350 | MEDIUM | 5.4 | 0.6% | Apr 27, 2023 | A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b... |
| CVE-2023-2349 | MEDIUM | 5.4 | 0.6% | Apr 27, 2023 | A vulnerability classified as problematic has been found in SourceCodester Service Provider Management System 1.0. Affec... |
| CVE-2023-30847 | HIGH | 8.2 | 0.9% | Apr 27, 2023 | H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain ty... |
| CVE-2023-30338 | MEDIUM | 5.4 | 0.4% | Apr 27, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web... |
| CVE-2023-2348 | CRITICAL | 9.8 | 0.8% | Apr 27, 2023 | A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been rated as critical. This ... |
| CVE-2023-2347 | CRITICAL | 9.8 | 0.8% | Apr 27, 2023 | A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. Th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now