2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48256MEDIUM6.3The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies ...
CVE-2023-48255MEDIUM6.1The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary clie...
CVE-2023-48254MEDIUM6.1The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses...
CVE-2023-48253HIGH8.8The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication datab...
CVE-2023-48252HIGH8.8The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft...
CVE-2023-48251CRITICAL9.8The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard...
CVE-2023-48250CRITICAL9.8The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple ...
CVE-2023-48249MEDIUM6.5The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the...
CVE-2023-48248MEDIUM5.4The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary...
CVE-2023-48247HIGH7.5The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application...
CVE-2023-48246MEDIUM6.5The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of t...
CVE-2023-48245CRITICAL9.8The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the applicati...
CVE-2023-48244MEDIUM6.1The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses...
CVE-2023-48243HIGH8.8The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the...
CVE-2023-48242MEDIUM6.5The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under t...
CVE-2023-51252MEDIUM5.4PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is ...
CVE-2023-50120MEDIUM5.5MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc...
CVE-2023-49619LOW3.1Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ...
CVE-2023-49471HIGH8.8Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validat...
CVE-2023-49427HIGH7.5Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via...
CVE-2023-49394MEDIUM6.1Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
CVE-2023-48864HIGH7.5SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
CVE-2023-41603MEDIUM5.3D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to...
CVE-2023-41781MEDIUM6.1 There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interfac...
CVE-2023-31446CRITICAL9.8In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now