2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1688 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This af... |
| CVE-2023-1687 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected i... |
| CVE-2023-1686 | MEDIUM | 6.1 | 0.5% | Mar 29, 2023 | A vulnerability was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. It has been rated as problematic. T... |
| CVE-2023-1685 | HIGH | 7.2 | 4.1% | Mar 29, 2023 | A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown c... |
| CVE-2023-23355 | HIGH | 7.2 | 1.2% | Mar 29, 2023 | An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit... |
| CVE-2023-1684 | CRITICAL | 9.8 | 0.9% | Mar 29, 2023 | A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the f... |
| CVE-2023-1683 | HIGH | 7.5 | 0.5% | Mar 29, 2023 | A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown funct... |
| CVE-2023-1682 | HIGH | 7.5 | 0.7% | Mar 29, 2023 | A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an un... |
| CVE-2023-27232 | CRITICAL | 9.8 | 1.9% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy p... |
| CVE-2023-1681 | HIGH | 7.5 | 0.8% | Mar 28, 2023 | A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of t... |
| CVE-2023-27231 | CRITICAL | 9.8 | 2.0% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parame... |
| CVE-2023-27229 | CRITICAL | 9.8 | 2.0% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw paramete... |
| CVE-2023-1679 | HIGH | 7.8 | 0.3% | Mar 28, 2023 | A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9... |
| CVE-2023-1678 | HIGH | 7.8 | 0.2% | Mar 28, 2023 | A vulnerability classified as critical has been found in DriverGenius 9.70.0.346. This affects the function 0x9C40A0D8/0... |
| CVE-2023-1677 | MEDIUM | 5.5 | 0.2% | Mar 28, 2023 | A vulnerability was found in DriverGenius 9.70.0.346. It has been rated as problematic. Affected by this issue is the fu... |
| CVE-2023-28718 | HIGH | 8 | 0.3% | Mar 28, 2023 | Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any che... |
| CVE-2023-28712 | CRITICAL | 9.8 | 1.2% | Mar 28, 2023 | Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system ... |
| CVE-2023-28654 | CRITICAL | 9.8 | 0.8% | Mar 28, 2023 | Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full... |
| CVE-2023-28648 | MEDIUM | 6.1 | 0.8% | Mar 28, 2023 | Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to... |
| CVE-2023-28637 | HIGH | 8.8 | 1.3% | Mar 28, 2023 | DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and t... |
| CVE-2023-28631 | CRITICAL | 9.8 | 1.3% | Mar 28, 2023 | comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A Comrak AST can be constructed ma... |
| CVE-2023-28626 | HIGH | 7.5 | 1.1% | Mar 28, 2023 | comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A range of quadratic parsing issue... |
| CVE-2023-28447 | MEDIUM | 6.1 | 1.0% | Mar 28, 2023 | Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker co... |
| CVE-2023-28427 | HIGH | 8.2 | 1.2% | Mar 28, 2023 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent w... |
| CVE-2023-28398 | CRITICAL | 9.8 | 0.9% | Mar 28, 2023 | Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now