2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-28356HIGH7.5A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can ca...
CVE-2023-32058HIGH7.5Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing ove...
CVE-2023-31497HIGH7.8Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 a...
CVE-2023-2444HIGH8.8 A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability...
CVE-2023-2443HIGH7.5 Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure ...
CVE-2023-29031HIGH7.1 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potential...
CVE-2023-29030HIGH7.1 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potential...
CVE-2023-29400HIGH7.3Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in out...
CVE-2023-24539HIGH7.3Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multip...
CVE-2023-0857HIGH7.5Unintentional change of settings during initial registration of system administrators which uses control protocols. The ...
CVE-2023-2649HIGH8.8A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unk...
CVE-2023-2647HIGH8.8A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown func...
CVE-2023-2644HIGH7.8A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affe...
CVE-2023-31477HIGH7.5A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible ...
CVE-2023-31442HIGH7.5In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootst...
CVE-2023-30172HIGH7.5A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers...
CVE-2023-32080HIGH8.8Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions ...
CVE-2023-31161HIGH8.8An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (S...
CVE-2023-31152HIGH8.8An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Rea...
CVE-2023-31149HIGH8.8 An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller...
CVE-2023-31148HIGH8.8An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller ...
CVE-2023-31568HIGH8.8Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
CVE-2023-31567HIGH8.8Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAES...
CVE-2023-31566HIGH8.8Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted...
CVE-2023-30356HIGH7.5Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now