2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38733MEDIUM4.3 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated us...
CVE-2023-4475MEDIUM5.5An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file r...
CVE-2023-4212MEDIUM6.8 ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to ...
CVE-2023-3699MEDIUM5.5An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users...
CVE-2023-39599MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted pay...
CVE-2023-38996MEDIUM6.7An issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via...
CVE-2023-38732MEDIUM4.3 IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive informa...
CVE-2023-38668MEDIUM5.5Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).
CVE-2023-38667MEDIUM5.5Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.
CVE-2023-38666MEDIUM5.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in...
CVE-2023-38665MEDIUM5.5Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).
CVE-2023-37440MEDIUM5.3A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2023-37439MEDIUM6.1Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37438MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37437MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37436MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37435MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37425MEDIUM6.1A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2023-37423MEDIUM5.4Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2023-37422MEDIUM5.4Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2023-37421MEDIUM5.4Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2023-24516MEDIUM5.4Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal...
CVE-2023-24515MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the...
CVE-2023-24514MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users ses...
CVE-2023-23565MEDIUM4.9An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to retrieve PHP files from the...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now