2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-46098HIGH8.8A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from...
CVE-2023-46097HIGH8A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does ...
CVE-2023-45794HIGH8.1A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications...
CVE-2023-44374HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM...
CVE-2023-44317HIGH8.6A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDC...
CVE-2023-43503HIGH7.5A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks ...
CVE-2023-47609HIGH8.8SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute ...
CVE-2023-45880HIGH7.2GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can crea...
CVE-2023-42326HIGH8.8An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the inte...
CVE-2023-45560HIGH7.5An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel acce...
CVE-2023-45558HIGH7.5An issue in Golden v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
CVE-2023-47629HIGH8DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restr...
CVE-2023-31403HIGH8SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB sh...
CVE-2023-47346HIGH7.5Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service v...
CVE-2023-47117HIGH7.5Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the appl...
CVE-2023-47621HIGH8.8Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In af...
CVE-2023-6101HIGH7.5A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. T...
CVE-2023-48060HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
CVE-2023-48058HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
CVE-2023-6097HIGH8.8A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089. This vulnerabili...
CVE-2023-5747HIGH8.8Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation o...
CVE-2023-5037HIGH7.2badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An at...
CVE-2023-47163HIGH7.5Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack....
CVE-2023-46207HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue...
CVE-2023-35041HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now