2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31285MEDIUM6.1An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some sp...
CVE-2023-28697CRITICAL9.8Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vu...
CVE-2023-24836HIGH8.8SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker wit...
CVE-2023-22901MEDIUM4.9ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit...
CVE-2023-20853CRITICAL9.8aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message ...
CVE-2023-20852CRITICAL9.8aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauth...
CVE-2023-26246HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp...
CVE-2023-26245HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp...
CVE-2023-26244HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM...
CVE-2023-26243HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry...
CVE-2023-25292MEDIUM6.1Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated pr...
CVE-2023-2297HIGH8.1The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password...
CVE-2023-1786MEDIUM5.5Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to f...
CVE-2023-27107HIGH8.8Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server b...
CVE-2023-30846HIGH7.5typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-r...
CVE-2023-30845CRITICAL9.8ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 thr...
CVE-2023-30843MEDIUM6.5Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access t...
CVE-2023-30363CRITICAL9.8vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions...
CVE-2023-2291HIGH7.8Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine ...
CVE-2023-29443MEDIUM4.9Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and...
CVE-2023-29442MEDIUM6.1Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
CVE-2023-30280CRITICAL9.8Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote a...
CVE-2023-29836MEDIUM6.1Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attack...
CVE-2023-29835HIGH7.8Insecure Permission vulnerability found in Wondershare Dr.Fone v.12.9.6 allows a remote attacker to escalate privileges ...
CVE-2023-29596HIGH7.8Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a den...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now