2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50935MEDIUM6.5IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker ...
CVE-2023-50934MEDIUM5.3IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when co...
CVE-2023-50328MEDIUM5.3IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM...
CVE-2023-48793CRITICAL9.8Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
CVE-2023-48792CRITICAL9.8Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
CVE-2023-46344MEDIUM5.4A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an att...
CVE-2023-32333CRITICAL9.8IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access con...
CVE-2023-50940CRITICAL9.8IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privi...
CVE-2023-50937HIGH7.5IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt...
CVE-2023-50936HIGH8.8IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impers...
CVE-2023-50933MEDIUM6.1IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which...
CVE-2023-50327MEDIUM5.3IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized fil...
CVE-2023-50326HIGH7.5IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute for...
CVE-2023-50939HIGH7.5IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt...
CVE-2023-6221MEDIUM6.5 The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the prog...
CVE-2023-49617CRITICAL9.1 The MachineSense application programmable interface (API) is improperly protected and can be accessed without authe...
CVE-2023-49610HIGH8.1 MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on a...
CVE-2023-49115HIGH7.5 MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u...
CVE-2023-47867HIGH8.8 MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect...
CVE-2023-46706CRITICAL9.8 Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
CVE-2023-36496HIGH8.8Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their...
CVE-2023-4472CRITICAL9.8Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled t...
CVE-2023-47257HIGH8.1ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted...
CVE-2023-47256MEDIUM5.5ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of ...
CVE-2023-5841CRITICAL9.1Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy S...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now