2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37230HIGH8.8Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
CVE-2023-37229HIGH8.8Loftware Spectrum before 5.1 allows SSRF.
CVE-2023-37227CRITICAL9.8Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
CVE-2023-37226CRITICAL9.8Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
CVE-2023-49069MEDIUM6.9A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech...
CVE-2023-30756HIGH8.2A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-30755MEDIUM5.9A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-2919MEDIUM4.3The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. ...
CVE-2023-28827HIGH8.2A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-50883MEDIUM6.1ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and theref...
CVE-2023-46809HIGH7.4Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL whi...
CVE-2023-39333MEDIUM5.3Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be ...
CVE-2023-30587HIGH7.5A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using ...
CVE-2023-30584HIGH7.7A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f...
CVE-2023-30583HIGH7.5fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--all...
CVE-2023-30582MEDIUM5.3A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the...
CVE-2023-51368MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2023-51367HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-51366MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2023-50366MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2023-50360HIGH8.8A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut...
CVE-2023-47563HIGH8.8An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could a...
CVE-2023-45038HIGH8.8An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability coul...
CVE-2023-39300HIGH7.2An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allo...
CVE-2023-39298HIGH7.8A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now