2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20025CRITICAL9.8A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co...
CVE-2023-20020HIGH8.6A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco...
CVE-2023-20019MEDIUM6.1A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWork...
CVE-2023-20018MEDIUM6.5A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut...
CVE-2023-20010HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2023-20008HIGH7.1A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to ...
CVE-2023-20007HIGH7.2A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ...
CVE-2023-20002MEDIUM4.4A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass acce...
CVE-2023-22373MEDIUM5.4Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated att...
CVE-2023-22339HIGH7.5Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticate...
CVE-2023-22334MEDIUM5.3Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and ea...
CVE-2023-22331HIGH7.5Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthentic...
CVE-2023-0410MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
CVE-2023-22745MEDIUM6.4tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 ...
CVE-2023-22741CRITICAL9.8Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions ...
CVE-2023-0126HIGH7.5Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated atta...
CVE-2023-0406MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0404MEDIUM5.4The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev...
CVE-2023-0403MEDIUM5.4The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4....
CVE-2023-0402MEDIUM5.4The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever...
CVE-2023-23690HIGH7 Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation v...
CVE-2023-0398MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0397MEDIUM6.5A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_co...
CVE-2023-0290MEDIUM4.3Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory ...
CVE-2023-0164HIGH8.8OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now