2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-4920HIGH8.8The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-40361HIGH7.8SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker ...
CVE-2023-46277HIGH7.8please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOC...
CVE-2023-34052HIGH7.8VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce...
CVE-2023-44385HIGH8.8The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. A...
CVE-2023-43345HIGH8.6Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-41899HIGH7.2Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a parti...
CVE-2023-41898HIGH7.8Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is...
CVE-2023-44690HIGH7.5Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-45823HIGH7.5Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-30132HIGH7.8An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptog...
CVE-2023-27795HIGH7.8An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
CVE-2023-27793HIGH7.8An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak ...
CVE-2023-27792HIGH7.8An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions ...
CVE-2023-40145HIGH8.8 In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to th...
CVE-2023-27791HIGH8.1An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.
CVE-2023-42435HIGH8.8 The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to pe...
CVE-2023-41089HIGH8.8 The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to ...
CVE-2023-5059HIGH7.8 Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead...
CVE-2023-39431HIGH7.8 Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an ...
CVE-2023-38128HIGH7.8An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specia...
CVE-2023-38127HIGH7.8An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted docum...
CVE-2023-35986HIGH7.8 Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a sta...
CVE-2023-34366HIGH7.8A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A special...
CVE-2023-45277HIGH7.5Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now