2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26847MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o...
CVE-2023-26846MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o...
CVE-2023-26845MEDIUM4.3A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via u...
CVE-2023-23277MEDIUM6.1Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML ...
CVE-2023-1552HIGH7.8ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI ...
CVE-2023-28062HIGH8.8 Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated mal...
CVE-2023-26964HIGH7.5An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE...
CVE-2023-0645CRITICAL9.1An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read ...
CVE-2023-27645CRITICAL9.8An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges v...
CVE-2023-27179HIGH7.5GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet...
CVE-2023-26917HIGH7.5libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat...
CVE-2023-1976HIGH8.8Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-29054HIGH7.4A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ...
CVE-2023-29053HIGH7.8A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The ...
CVE-2023-28828MEDIUM5.9A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Enti...
CVE-2023-28766HIGH7.5A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300...
CVE-2023-28489CRITICAL9.8A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver...
CVE-2023-27464MEDIUM5.3A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forg...
CVE-2023-26293HIGH7.3A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int...
CVE-2023-23588MEDIUM6.3A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Stora...
CVE-2023-1975MEDIUM6.5Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-1974MEDIUM6.5Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-28368MEDIUM5.7TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH h...
CVE-2023-27917HIGH8.8OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can acce...
CVE-2023-27520MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote una...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now