2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22574HIGH8.1 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in pl...
CVE-2023-22573MEDIUM5.5Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloud...
CVE-2023-0613HIGH7.5A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. Affected by this vulnerabilit...
CVE-2023-0612HIGH7.5A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. Affected is an unknown fun...
CVE-2023-0611HIGH8.8A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects som...
CVE-2023-23692HIGH8.8 Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacke...
CVE-2023-22572HIGH7.8 Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in chan...
CVE-2023-0610MEDIUM4.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
CVE-2023-0609MEDIUM4.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
CVE-2023-24977HIGH7.5Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1....
CVE-2023-0115Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-0608MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2023-0607MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
CVE-2023-23846HIGH7.5Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsi...
CVE-2023-20856HIGH8.8VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the v...
CVE-2023-0587CRITICAL9.1A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length heade...
CVE-2023-0524HIGH8.8As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This co...
CVE-2023-0454HIGH8.1OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. Th...
CVE-2023-23928CRITICAL9.8reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This all...
CVE-2023-23630MEDIUM6.1Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Exp...
CVE-2023-0606MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
CVE-2023-24956HIGH8.8Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php...
CVE-2023-24241CRITICAL9.8Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/l...
CVE-2023-23924CRITICAL9.8Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image...
CVE-2023-0341HIGH7.8A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now