2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24236CRITICAL9.8TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province par...
CVE-2023-22580HIGH7.5Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclos...
CVE-2023-22579HIGH8.8Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
CVE-2023-22578CRITICAL9.8Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
CVE-2023-0862HIGH8.8The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file upl...
CVE-2023-0860HIGH7.5Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
CVE-2023-0861HIGH8.8NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful...
CVE-2023-0662HIGH7.5In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload ca...
CVE-2023-0568HIGH8.1In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer on...
CVE-2023-0850HIGH7.5A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown ...
CVE-2023-0849CRITICAL9.8A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unk...
CVE-2023-0848HIGH7.5A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unkn...
CVE-2023-22855CRITICAL9.8Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 808...
CVE-2023-24499MEDIUM4.6Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, ...
CVE-2023-24498HIGH7.5An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow d...
CVE-2023-23850MEDIUM4.3A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read perm...
CVE-2023-23848MEDIUM4.3Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permis...
CVE-2023-23847LOW3.5A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers...
CVE-2023-23836HIGH7.2SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerab...
CVE-2023-23467MEDIUM6.1Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
CVE-2023-23466HIGH7.5Media CP Media Control Panel latest version. Insufficiently protected credential change.
CVE-2023-23465HIGH8.8Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
CVE-2023-23464HIGH7.5Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
CVE-2023-23463HIGH7.5Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request...
CVE-2023-23462CRITICAL9.8Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now