2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37822HIGH8.2The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serve...
CVE-2023-7273MEDIUM6.8Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has ...
CVE-2023-3441CRITICAL9.1An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not s...
CVE-2023-46175MEDIUM4.9IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which...
CVE-2023-52950MEDIUM5.3Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent befor...
CVE-2023-52949MEDIUM5.5Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for...
CVE-2023-52948MEDIUM5Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agen...
CVE-2023-52947LOW3.3Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Busines...
CVE-2023-52946HIGH8.2Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synolog...
CVE-2023-51157MEDIUM5.4Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obt...
CVE-2023-25189LOW3.3BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web E...
CVE-2023-5359HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including...
CVE-2023-26691HIGH7.2Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafte...
CVE-2023-26690HIGH8.8File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/E...
CVE-2023-26689CRITICAL9.8An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted ...
CVE-2023-26688MEDIUM5.4Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via...
CVE-2023-26687HIGH8.8Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information ...
CVE-2023-26686CRITICAL9.8File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo...
CVE-2023-7282MEDIUM4.3Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc...
CVE-2023-7281MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor...
CVE-2023-46948MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attac...
CVE-2023-47480HIGH8.4An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () functi...
CVE-2023-27584CRITICAL9.8Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native ...
CVE-2023-30464HIGH7.5CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
CVE-2023-41612HIGH8.8Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now