2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50948CRITICAL9.8IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, whi...
CVE-2023-7214HIGH8.8A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by ...
CVE-2023-7213HIGH8.8A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerabilit...
CVE-2023-47145HIGH7.8IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privil...
CVE-2023-7212CRITICAL9.8A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the f...
CVE-2023-7211HIGH8.1A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown cod...
CVE-2023-7210CRITICAL9.8A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of th...
CVE-2023-7209HIGH7.5A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unkn...
CVE-2023-7208CRITICAL9.8A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects...
CVE-2023-51441HIGH7.2** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the ...
CVE-2023-6801MEDIUM5.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-6798MEDIUM5.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-50121MEDIUM5.7Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
CVE-2023-46953CRITICAL9.8SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in...
CVE-2023-50609MEDIUM6.1Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote a...
CVE-2023-39853MEDIUM6.5SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the d...
CVE-2023-50612HIGH7.8Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate pri...
CVE-2023-47560HIGH8.8An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow a...
CVE-2023-47559MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could al...
CVE-2023-47219HIGH8.8A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authentic...
CVE-2023-46837LOW3.3Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allo...
CVE-2023-46836MEDIUM4.7The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was ...
CVE-2023-46835MEDIUM5.5The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an...
CVE-2023-45044HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-45043HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now