2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51105HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompr...
CVE-2023-51104HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_...
CVE-2023-51103HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_...
CVE-2023-49949HIGH8.1Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit...
CVE-2023-50968HIGH7.5Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri cal...
CVE-2023-5180HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used...
CVE-2023-51363MEDIUM6.5VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's ...
CVE-2023-50339MEDIUM5.4Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v...
CVE-2023-50332MEDIUM6.5Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6...
CVE-2023-50294MEDIUM6.5The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As ...
CVE-2023-50175MEDIUM5.4Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/ma...
CVE-2023-49807MEDIUM5.4Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this ...
CVE-2023-49779MEDIUM5.4Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerabil...
CVE-2023-49598MEDIUM5.4Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0...
CVE-2023-49119MEDIUM5.4Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerabili...
CVE-2023-47215MEDIUM5.4Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prio...
CVE-2023-46711MEDIUM4.6VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the p...
CVE-2023-46699MEDIUM4.3Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0...
CVE-2023-46681HIGH7.8Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ve...
CVE-2023-45741MEDIUM6.8VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute a...
CVE-2023-45740MEDIUM5.4Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If th...
CVE-2023-45737MEDIUM5.4Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin...
CVE-2023-42436MEDIUM5.4Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this ...
CVE-2023-51654MEDIUM5.5Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions ...
CVE-2023-50297MEDIUM6.1Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to r...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now