2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-5032HIGH7.2A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by this issue is some unk...
CVE-2023-41349HIGH8.8 ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN f...
CVE-2023-35851HIGH7.5 SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can i...
CVE-2023-35850HIGH7.2 SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote a...
CVE-2023-5030HIGH8.8A vulnerability has been found in Tongda OA up to 11.10 and classified as critical. This vulnerability affects unknown c...
CVE-2023-5029HIGH8.8A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /cat...
CVE-2023-5027HIGH7.5A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulner...
CVE-2023-5023HIGH8.8A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functiona...
CVE-2023-5022HIGH8.8A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an...
CVE-2023-5012HIGH7.8A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of...
CVE-2023-3025HIGH7.2The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includ...
CVE-2023-36562HIGH7.1Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-41886HIGH7.5OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file r...
CVE-2023-0813HIGH7.5A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is s...
CVE-2023-40018HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-4991HIGH7.8A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknow...
CVE-2023-4987HIGH8A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue...
CVE-2023-4985HIGH7.8A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown fun...
CVE-2023-42270HIGH8.8Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-4665HIGH8.8Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This iss...
CVE-2023-4664HIGH8.8Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects ...
CVE-2023-36658HIGH7.8An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused loca...
CVE-2023-38039HIGH7.5When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl ...
CVE-2023-3891HIGH7Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system
CVE-2023-40958HIGH8.8A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now