2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29849HIGH8.8Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice...
CVE-2023-29848MEDIUM4.8Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in...
CVE-2023-29480HIGH7.5Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
CVE-2023-29479MEDIUM5.3Ribose RNP before 0.16.3 may hang when the input is malformed.
CVE-2023-24820HIGH7.5RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-24819CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-24818HIGH7.5RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-30369CRITICAL9.8Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
CVE-2023-30368CRITICAL9.8Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.
CVE-2023-29570MEDIUM5.5Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerabil...
CVE-2023-23892MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jamie Poitra M Chart plugin <= 1.9.4 versions.
CVE-2023-1731HIGH7.2In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the i...
CVE-2023-29583MEDIUM5.5yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note...
CVE-2023-29582MEDIUM5.5yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note...
CVE-2023-29579MEDIUM5.5yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: ...
CVE-2023-29578HIGH8.8mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty...
CVE-2023-25133CRITICAL9.8Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 a...
CVE-2023-25132CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote fo...
CVE-2023-25131CRITICAL9.8Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Bus...
CVE-2023-22581CRITICAL9.8White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under th...
CVE-2023-22577HIGH7.5Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password h...
CVE-2023-31045MEDIUM4.8A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attack...
CVE-2023-30533HIGH7.8SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlie...
CVE-2023-30458MEDIUM5.3A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious u...
CVE-2023-31085MEDIUM5.5An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now