2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-42488HIGH7.5 EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-41372HIGH7.8The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of...
CVE-2023-41255HIGH8.8The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on t...
CVE-2023-3112HIGH7.8A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker wi...
CVE-2023-39740HIGH8.2The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token an...
CVE-2023-39739HIGH8.2The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token...
CVE-2023-39737HIGH8.2The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send cra...
CVE-2023-39736HIGH8.2The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token...
CVE-2023-39735HIGH8.2The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token an...
CVE-2023-39734HIGH8.2The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the cha...
CVE-2023-39733HIGH8.2The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send...
CVE-2023-39732HIGH8.2The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token a...
CVE-2023-39619HIGH7.5ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpS...
CVE-2023-39219HIGH7.5PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java ...
CVE-2023-38041HIGH7A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p...
CVE-2023-37913HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-37912HIGH8.8XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior t...
CVE-2023-37910HIGH8.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t...
CVE-2023-37909HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-31582HIGH7.5jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
CVE-2023-27377HIGH7.5Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application ...
CVE-2023-27376HIGH7.5Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an...
CVE-2023-27375HIGH7.5Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 an...
CVE-2023-27259HIGH7.5Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows e...
CVE-2023-27258HIGH7.5Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier all...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now