2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37230 | HIGH | 8.8 | 0.3% | Sep 10, 2024 | Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. |
| CVE-2023-37229 | HIGH | 8.8 | 0.3% | Sep 10, 2024 | Loftware Spectrum before 5.1 allows SSRF. |
| CVE-2023-37227 | CRITICAL | 9.8 | 0.6% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. |
| CVE-2023-37226 | CRITICAL | 9.8 | 0.6% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. |
| CVE-2023-49069 | MEDIUM | 6.9 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech... |
| CVE-2023-30756 | HIGH | 8.2 | 0.5% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-30755 | MEDIUM | 5.9 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-2919 | MEDIUM | 4.3 | 0.2% | Sep 10, 2024 | The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. ... |
| CVE-2023-28827 | HIGH | 8.2 | 0.5% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-50883 | MEDIUM | 6.1 | 0.6% | Sep 9, 2024 | ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and theref... |
| CVE-2023-46809 | HIGH | 7.4 | 1.3% | Sep 7, 2024 | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL whi... |
| CVE-2023-39333 | MEDIUM | 5.3 | 0.9% | Sep 7, 2024 | Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be ... |
| CVE-2023-30587 | HIGH | 7.5 | 0.7% | Sep 7, 2024 | A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using ... |
| CVE-2023-30584 | HIGH | 7.7 | 0.4% | Sep 7, 2024 | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f... |
| CVE-2023-30583 | HIGH | 7.5 | 0.7% | Sep 7, 2024 | fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--all... |
| CVE-2023-30582 | MEDIUM | 5.3 | 0.6% | Sep 7, 2024 | A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the... |
| CVE-2023-51368 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2023-51367 | HIGH | 8.8 | 0.4% | Sep 6, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-51366 | MEDIUM | 6.5 | 0.5% | Sep 6, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2023-50366 | MEDIUM | 4.8 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-50360 | HIGH | 8.8 | 0.4% | Sep 6, 2024 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut... |
| CVE-2023-47563 | HIGH | 8.8 | 1.0% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could a... |
| CVE-2023-45038 | HIGH | 8.8 | 1.2% | Sep 6, 2024 | An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability coul... |
| CVE-2023-39300 | HIGH | 7.2 | 1.2% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allo... |
| CVE-2023-39298 | HIGH | 7.8 | 0.1% | Sep 6, 2024 | A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now