2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37261 | HIGH | 8.8 | 0.6% | Jul 7, 2023 | OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every versi... |
| CVE-2023-36992 | HIGH | 7.2 | 1.0% | Jul 7, 2023 | PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP ... |
| CVE-2023-36201 | HIGH | 7.5 | 0.5% | Jul 7, 2023 | An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted scri... |
| CVE-2023-33664 | HIGH | 8.8 | 0.8% | Jul 7, 2023 | ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /incl... |
| CVE-2023-25201 | HIGH | 8.8 | 0.5% | Jul 7, 2023 | Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows ... |
| CVE-2023-3534 | HIGH | 7.5 | 0.5% | Jul 7, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk... |
| CVE-2023-32183 | HIGH | 7.8 | 0.2% | Jul 7, 2023 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hac... |
| CVE-2023-37192 | HIGH | 7.5 | 0.5% | Jul 7, 2023 | Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within... |
| CVE-2023-35120 | HIGH | 8.8 | 0.2% | Jul 7, 2023 | PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send... |
| CVE-2023-31277 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | PiiGAB M-Bus transmits credentials in plaintext format. |
| CVE-2023-20899 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno... |
| CVE-2023-35934 | HIGH | 8.2 | 0.9% | Jul 6, 2023 | yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down... |
| CVE-2023-30195 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can ... |
| CVE-2023-3529 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unk... |
| CVE-2023-36461 | HIGH | 7.5 | 1.1% | Jul 6, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Masto... |
| CVE-2023-36456 | HIGH | 7.3 | 0.6% | Jul 6, 2023 | authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the so... |
| CVE-2023-37260 | HIGH | 7.5 | 0.8% | Jul 6, 2023 | league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2... |
| CVE-2023-36830 | HIGH | 7.8 | 0.4% | Jul 6, 2023 | SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files,... |
| CVE-2023-34193 | HIGH | 8.8 | 1.2% | Jul 6, 2023 | File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obt... |
| CVE-2023-36969 | HIGH | 8.8 | 44.8% | Jul 6, 2023 | CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. |
| CVE-2023-30325 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | SQL Injection vulnerability in textMessage parameter in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine v.1.0, all... |
| CVE-2023-30323 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | SQL Injection vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows atta... |
| CVE-2023-25583 | HIGH | 7.2 | 3.4% | Jul 6, 2023 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec... |
| CVE-2023-25582 | HIGH | 7.2 | 3.4% | Jul 6, 2023 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec... |
| CVE-2023-25124 | HIGH | 7.2 | 1.4% | Jul 6, 2023 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now