2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1688MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This af...
CVE-2023-1687MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected i...
CVE-2023-1686MEDIUM6.1A vulnerability was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. It has been rated as problematic. T...
CVE-2023-1685HIGH7.2A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown c...
CVE-2023-23355HIGH7.2An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit...
CVE-2023-1684CRITICAL9.8A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the f...
CVE-2023-1683HIGH7.5A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown funct...
CVE-2023-1682HIGH7.5A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an un...
CVE-2023-27232CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy p...
CVE-2023-1681HIGH7.5A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of t...
CVE-2023-27231CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parame...
CVE-2023-27229CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw paramete...
CVE-2023-1679HIGH7.8A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9...
CVE-2023-1678HIGH7.8A vulnerability classified as critical has been found in DriverGenius 9.70.0.346. This affects the function 0x9C40A0D8/0...
CVE-2023-1677MEDIUM5.5A vulnerability was found in DriverGenius 9.70.0.346. It has been rated as problematic. Affected by this issue is the fu...
CVE-2023-28718HIGH8Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any che...
CVE-2023-28712CRITICAL9.8Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system ...
CVE-2023-28654CRITICAL9.8Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full...
CVE-2023-28648MEDIUM6.1Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to...
CVE-2023-28637HIGH8.8DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and t...
CVE-2023-28631CRITICAL9.8comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A Comrak AST can be constructed ma...
CVE-2023-28626HIGH7.5comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A range of quadratic parsing issue...
CVE-2023-28447MEDIUM6.1Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker co...
CVE-2023-28427HIGH8.2matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent w...
CVE-2023-28398CRITICAL9.8Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now