2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0949MEDIUM4.8Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.
CVE-2023-26314HIGH8.8The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-e...
CVE-2023-24108CRITICAL9.8MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request pa...
CVE-2023-24107CRITICAL9.8hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution back...
CVE-2023-0947CRITICAL9.8Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2023-20858HIGH7.2VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injectio...
CVE-2023-20855HIGH8.8VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administra...
CVE-2023-24081MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attac...
CVE-2023-24080CRITICAL9.8A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to co...
CVE-2023-25157CRITICAL9.8GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServ...
CVE-2023-24320CRITICAL9.8An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via u...
CVE-2023-25812HIGH8.8Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGover...
CVE-2023-25811MEDIUM5.4Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a pers...
CVE-2023-25810MEDIUM5.4Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persisten...
CVE-2023-25657CRITICAL9.8Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7...
CVE-2023-25158CRITICAL9.8GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filte...
CVE-2023-0946CRITICAL9.8A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by ...
CVE-2023-0945MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affect...
CVE-2023-0943HIGH8.8A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. T...
CVE-2023-0942MEDIUM6.1The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ paramet...
CVE-2023-23009MEDIUM6.5Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS pa...
CVE-2023-22984MEDIUM6.1A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administra...
CVE-2023-22920CRITICAL9.8A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a fac...
CVE-2023-24184CRITICAL9.8TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
CVE-2023-0934MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now