2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5502HIGH8.2On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en...
CVE-2023-52951MEDIUM5.9A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ...
CVE-2023-52945HIGH7.8Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13...
CVE-2023-7346MEDIUM4.1Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i...
CVE-2023-7345MEDIUM6.9Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th...
CVE-2023-24215CRITICAL9.1Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers...
CVE-2023-31317HIGH8.8Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an...
CVE-2023-31316HIGH7.1Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P...
CVE-2023-31309MEDIUM6.8Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload...
CVE-2023-30059MEDIUM5.4An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use...
CVE-2023-27753HIGH8An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c...
CVE-2023-46453CRITICAL9.8Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device...
CVE-2023-47268MEDIUM5.3In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar...
CVE-2023-42346HIGH7.5Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
CVE-2023-42345MEDIUM6.1A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
CVE-2023-42344HIGH7.3Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/...
CVE-2023-42343MEDIUM6.1A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
CVE-2023-54349MEDIUM6.1AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject...
CVE-2023-54348HIGH8.8ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas...
CVE-2023-54347HIGH8.7OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect...
CVE-2023-54346HIGH8.7WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att...
CVE-2023-54345HIGH8.8Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated us...
CVE-2023-54344CRITICAL9.8Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attack...
CVE-2023-54342CRITICAL9.8Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface th...
CVE-2023-20585MEDIUM5.6Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hy...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now