2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20025 | CRITICAL | 9.8 | 1.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co... |
| CVE-2023-20020 | HIGH | 8.6 | 0.9% | Jan 20, 2023 | A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco... |
| CVE-2023-20019 | MEDIUM | 6.1 | 0.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWork... |
| CVE-2023-20018 | MEDIUM | 6.5 | 0.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut... |
| CVE-2023-20010 | HIGH | 8.8 | 0.9% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2023-20008 | HIGH | 7.1 | 0.2% | Jan 20, 2023 | A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to ... |
| CVE-2023-20007 | HIGH | 7.2 | 0.7% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ... |
| CVE-2023-20002 | MEDIUM | 4.4 | 0.2% | Jan 20, 2023 | A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass acce... |
| CVE-2023-22373 | MEDIUM | 5.4 | 1.9% | Jan 20, 2023 | Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated att... |
| CVE-2023-22339 | HIGH | 7.5 | 1.1% | Jan 20, 2023 | Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticate... |
| CVE-2023-22334 | MEDIUM | 5.3 | 0.9% | Jan 20, 2023 | Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and ea... |
| CVE-2023-22331 | HIGH | 7.5 | 1.0% | Jan 20, 2023 | Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthentic... |
| CVE-2023-0410 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5. |
| CVE-2023-22745 | MEDIUM | 6.4 | 0.5% | Jan 19, 2023 | tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 ... |
| CVE-2023-22741 | CRITICAL | 9.8 | 2.4% | Jan 19, 2023 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions ... |
| CVE-2023-0126 | HIGH | 7.5 | 72.7% | Jan 19, 2023 | Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated atta... |
| CVE-2023-0406 | MEDIUM | 4.3 | 0.4% | Jan 19, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-0404 | MEDIUM | 5.4 | 0.5% | Jan 19, 2023 | The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev... |
| CVE-2023-0403 | MEDIUM | 5.4 | 0.4% | Jan 19, 2023 | The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.... |
| CVE-2023-0402 | MEDIUM | 5.4 | 0.8% | Jan 19, 2023 | The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever... |
| CVE-2023-23690 | HIGH | 7 | 0.2% | Jan 19, 2023 | Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation v... |
| CVE-2023-0398 | MEDIUM | 6.5 | 0.3% | Jan 19, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-0397 | MEDIUM | 6.5 | 0.5% | Jan 19, 2023 | A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_co... |
| CVE-2023-0290 | MEDIUM | 4.3 | 0.7% | Jan 18, 2023 | Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory ... |
| CVE-2023-0164 | HIGH | 8.8 | 1.4% | Jan 18, 2023 | OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now