2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22733 | MEDIUM | 6.5 | 0.7% | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module ... |
| CVE-2023-22732 | CRITICAL | 9.8 | 0.7% | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio... |
| CVE-2023-22731 | HIGH | 8.8 | 1.3% | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the ... |
| CVE-2023-22730 | HIGH | 7.5 | 0.7% | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible... |
| CVE-2023-23637 | HIGH | 7.6 | 0.6% | Jan 17, 2023 | IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to t... |
| CVE-2023-22727 | CRITICAL | 9.8 | 0.9% | Jan 17, 2023 | CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\D... |
| CVE-2023-22499 | HIGH | 7.5 | 0.6% | Jan 17, 2023 | Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to ... |
| CVE-2023-0296 | MEDIUM | 5.3 | 0.3% | Jan 17, 2023 | The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on ... |
| CVE-2023-0122 | HIGH | 7.5 | 1.3% | Jan 17, 2023 | A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attack... |
| CVE-2023-23749 | HIGH | 7.5 | 0.6% | Jan 17, 2023 | The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Inject... |
| CVE-2023-22624 | HIGH | 7.5 | 3.2% | Jan 17, 2023 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. |
| CVE-2023-22875 | HIGH | 7.5 | 0.3% | Jan 17, 2023 | IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed ho... |
| CVE-2023-0158 | HIGH | 7.5 | 0.7% | Jan 17, 2023 | NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" en... |
| CVE-2023-0338 | MEDIUM | 6.1 | 0.5% | Jan 17, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. |
| CVE-2023-0337 | MEDIUM | 6.1 | 0.5% | Jan 17, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. |
| CVE-2023-22366 | HIGH | 7.8 | 0.2% | Jan 17, 2023 | CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a speci... |
| CVE-2023-22357 | CRITICAL | 9.8 | 1.2% | Jan 17, 2023 | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS ... |
| CVE-2023-22316 | MEDIUM | 6.5 | 0.3% | Jan 17, 2023 | Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a networ... |
| CVE-2023-22304 | HIGH | 8 | 0.9% | Jan 17, 2023 | OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a networ... |
| CVE-2023-22303 | CRITICAL | 9.8 | 0.9% | Jan 17, 2023 | TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerabil... |
| CVE-2023-22298 | MEDIUM | 6.1 | 0.9% | Jan 17, 2023 | Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a ... |
| CVE-2023-22296 | MEDIUM | 6.1 | 0.5% | Jan 17, 2023 | Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prio... |
| CVE-2023-22286 | HIGH | 8.1 | 0.4% | Jan 17, 2023 | Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PB... |
| CVE-2023-22280 | HIGH | 7.2 | 1.0% | Jan 17, 2023 | MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an... |
| CVE-2023-22279 | CRITICAL | 9.8 | 1.1% | Jan 17, 2023 | MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now