2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26830HIGH7.2An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before...
CVE-2023-26829CRITICAL9.8An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows r...
CVE-2023-0432CRITICAL9 The web configuration service of the affected device contains an authenticated command injection vulnerability. It can ...
CVE-2023-0344HIGH7.5Akuvox E11 appears to be using a custom version of dropbear SSH server. This server allows an insecure option that by de...
CVE-2023-0343HIGH7.5Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, an...
CVE-2023-1777MEDIUM5.3Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost...
CVE-2023-1776MEDIUM5.4Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it usi...
CVE-2023-1775MEDIUM6.5When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_delete...
CVE-2023-1774MEDIUM5.4When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to...
CVE-2023-1773CRITICAL9.8A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of ...
CVE-2023-1772MEDIUM4.8A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part o...
CVE-2023-1771MEDIUM6.1A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affect...
CVE-2023-1770CRITICAL9.8A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affe...
CVE-2023-1769HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0...
CVE-2023-1060MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YKM YKM CRM allows...
CVE-2023-1258MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardw...
CVE-2023-28727HIGH8.8Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Fo...
CVE-2023-28726HIGH8.8Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.
CVE-2023-28756MEDIUM5.3A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles inval...
CVE-2023-28755MEDIUM5.3A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invali...
CVE-2023-1762HIGH8.8Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1761MEDIUM5.4Cross-site Scripting in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1760MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1759MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1755MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now