2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-6057HIGH7.4A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro...
CVE-2023-6056HIGH7.4A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro...
CVE-2023-6055HIGH7.4A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails ...
CVE-2023-6729HIGH7.3Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access ...
CVE-2023-32196HIGH7.5A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobject...
CVE-2023-32194HIGH8.6A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matt...
CVE-2023-32193HIGH8.3A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint...
CVE-2023-32192HIGH8.3A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API ...
CVE-2023-32190HIGH8.5mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file opera...
CVE-2023-22650HIGH8.8A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from ...
CVE-2023-7291HIGH8.1The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2023-50780HIGH8.8Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro...
CVE-2023-37154HIGH8.4check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and Permi...
CVE-2023-6362HIGH7.3A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf...
CVE-2023-6361HIGH7.3A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf...
CVE-2023-37822HIGH8.2The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serve...
CVE-2023-52946HIGH8.2Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synolog...
CVE-2023-5359HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including...
CVE-2023-26691HIGH7.2Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafte...
CVE-2023-26690HIGH8.8File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/E...
CVE-2023-26687HIGH8.8Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information ...
CVE-2023-47480HIGH8.4An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () functi...
CVE-2023-30464HIGH7.5CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
CVE-2023-41612HIGH8.8Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
CVE-2023-41610HIGH8.8Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now