2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22733MEDIUM6.5Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module ...
CVE-2023-22732CRITICAL9.8Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio...
CVE-2023-22731HIGH8.8Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the ...
CVE-2023-22730HIGH7.5Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible...
CVE-2023-23637HIGH7.6IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to t...
CVE-2023-22727CRITICAL9.8CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\D...
CVE-2023-22499HIGH7.5Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to ...
CVE-2023-0296MEDIUM5.3The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on ...
CVE-2023-0122HIGH7.5A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attack...
CVE-2023-23749HIGH7.5The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Inject...
CVE-2023-22624HIGH7.5Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
CVE-2023-22875HIGH7.5 IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed ho...
CVE-2023-0158HIGH7.5NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" en...
CVE-2023-0338MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
CVE-2023-0337MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
CVE-2023-22366HIGH7.8CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a speci...
CVE-2023-22357CRITICAL9.8Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS ...
CVE-2023-22316MEDIUM6.5Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a networ...
CVE-2023-22304HIGH8OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a networ...
CVE-2023-22303CRITICAL9.8TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerabil...
CVE-2023-22298MEDIUM6.1Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a ...
CVE-2023-22296MEDIUM6.1Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prio...
CVE-2023-22286HIGH8.1Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PB...
CVE-2023-22280HIGH7.2MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an...
CVE-2023-22279CRITICAL9.8MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now