2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45209HIGH7.5An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplin...
CVE-2023-43491HIGH7.5An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Sma...
CVE-2023-40146CRITICAL9.8A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A ...
CVE-2023-39367HIGH7.2An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 ...
CVE-2023-52644MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct queue in DMA Tx path w...
CVE-2023-51500HIGH7.7Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8.
CVE-2023-51418HIGH7.7Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: fr...
CVE-2023-52643MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iio: core: fix memleak in iio_device_register_sysfs...
CVE-2023-52642HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rc: bpf attach/detach requires write permiss...
CVE-2023-44227HIGH7.5Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a th...
CVE-2023-36505HIGH7.2Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contac...
CVE-2023-25043MEDIUM4.3Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from ...
CVE-2023-51391HIGH7.5A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially al...
CVE-2023-45000MEDIUM5.3Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n...
CVE-2023-40000MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...
CVE-2023-50872HIGH7.5The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses...
CVE-2023-33806HIGH7.8Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to exe...
CVE-2023-45503MEDIUM5.3SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denia...
CVE-2023-4857HIGH7.5 An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to exe...
CVE-2023-4856HIGH8.8 A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbi...
CVE-2023-4855HIGH7.2 A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat...
CVE-2023-48710CRITICAL9.8iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho...
CVE-2023-48709HIGH8iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' ...
CVE-2023-47626MEDIUM6.1iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible...
CVE-2023-47622MEDIUM6.1iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now