2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31285 | MEDIUM | 6.1 | 0.8% | Apr 27, 2023 | An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some sp... |
| CVE-2023-28697 | CRITICAL | 9.8 | 0.9% | Apr 27, 2023 | Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vu... |
| CVE-2023-24836 | HIGH | 8.8 | 1.2% | Apr 27, 2023 | SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker wit... |
| CVE-2023-22901 | MEDIUM | 4.9 | 0.9% | Apr 27, 2023 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit... |
| CVE-2023-20853 | CRITICAL | 9.8 | 1.0% | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message ... |
| CVE-2023-20852 | CRITICAL | 9.8 | 1.0% | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauth... |
| CVE-2023-26246 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp... |
| CVE-2023-26245 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp... |
| CVE-2023-26244 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM... |
| CVE-2023-26243 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry... |
| CVE-2023-25292 | MEDIUM | 6.1 | 0.8% | Apr 27, 2023 | Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated pr... |
| CVE-2023-2297 | HIGH | 8.1 | 1.0% | Apr 27, 2023 | The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password... |
| CVE-2023-1786 | MEDIUM | 5.5 | 0.3% | Apr 26, 2023 | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to f... |
| CVE-2023-27107 | HIGH | 8.8 | 0.8% | Apr 26, 2023 | Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server b... |
| CVE-2023-30846 | HIGH | 7.5 | 2.2% | Apr 26, 2023 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-r... |
| CVE-2023-30845 | CRITICAL | 9.8 | 0.7% | Apr 26, 2023 | ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 thr... |
| CVE-2023-30843 | MEDIUM | 6.5 | 0.6% | Apr 26, 2023 | Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access t... |
| CVE-2023-30363 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions... |
| CVE-2023-2291 | HIGH | 7.8 | 0.8% | Apr 26, 2023 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine ... |
| CVE-2023-29443 | MEDIUM | 4.9 | 3.0% | Apr 26, 2023 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and... |
| CVE-2023-29442 | MEDIUM | 6.1 | 9.4% | Apr 26, 2023 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. |
| CVE-2023-30280 | CRITICAL | 9.8 | 1.2% | Apr 26, 2023 | Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote a... |
| CVE-2023-29836 | MEDIUM | 6.1 | 0.6% | Apr 26, 2023 | Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attack... |
| CVE-2023-29835 | HIGH | 7.8 | 0.4% | Apr 26, 2023 | Insecure Permission vulnerability found in Wondershare Dr.Fone v.12.9.6 allows a remote attacker to escalate privileges ... |
| CVE-2023-29596 | HIGH | 7.8 | 0.3% | Apr 26, 2023 | Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a den... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now