2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5502 | HIGH | 8.2 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en... |
| CVE-2023-52951 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ... |
| CVE-2023-52945 | HIGH | 7.8 | 0.1% | May 27, 2026 | Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13... |
| CVE-2023-7346 | MEDIUM | 4.1 | 0.1% | May 20, 2026 | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i... |
| CVE-2023-7345 | MEDIUM | 6.9 | 0.3% | May 19, 2026 | Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th... |
| CVE-2023-24215 | CRITICAL | 9.1 | 0.2% | May 18, 2026 | Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers... |
| CVE-2023-31317 | HIGH | 8.8 | 0.1% | May 15, 2026 | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an... |
| CVE-2023-31316 | HIGH | 7.1 | 0.1% | May 15, 2026 | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P... |
| CVE-2023-31309 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload... |
| CVE-2023-30059 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use... |
| CVE-2023-27753 | HIGH | 8 | 0.3% | May 12, 2026 | An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c... |
| CVE-2023-46453 | CRITICAL | 9.8 | 0.8% | May 8, 2026 | Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device... |
| CVE-2023-47268 | MEDIUM | 5.3 | 0.7% | May 8, 2026 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar... |
| CVE-2023-42346 | HIGH | 7.5 | 0.2% | May 8, 2026 | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. |
| CVE-2023-42345 | MEDIUM | 6.1 | 0.1% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. |
| CVE-2023-42344 | HIGH | 7.3 | 2.2% | May 8, 2026 | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/... |
| CVE-2023-42343 | MEDIUM | 6.1 | 0.6% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. |
| CVE-2023-54349 | MEDIUM | 6.1 | 0.3% | May 5, 2026 | AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject... |
| CVE-2023-54348 | HIGH | 8.8 | 0.4% | May 5, 2026 | ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas... |
| CVE-2023-54347 | HIGH | 8.7 | 0.5% | May 5, 2026 | OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect... |
| CVE-2023-54346 | HIGH | 8.7 | 0.3% | May 5, 2026 | WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att... |
| CVE-2023-54345 | HIGH | 8.8 | 0.6% | May 5, 2026 | Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated us... |
| CVE-2023-54344 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attack... |
| CVE-2023-54342 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface th... |
| CVE-2023-20585 | MEDIUM | 5.6 | 0.1% | Apr 16, 2026 | Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hy... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now