2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48428HIGH7.2A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism ...
CVE-2023-48427CRITICAL9.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly v...
CVE-2023-46285HIGH7.5A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi...
CVE-2023-46284HIGH7.5A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi...
CVE-2023-46283HIGH7.5A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi...
CVE-2023-46282MEDIUM6.1A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi...
CVE-2023-46281HIGH8.8A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi...
CVE-2023-46156HIGH7.5Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to crea...
CVE-2023-38380HIGH8.7A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP...
CVE-2023-6727MEDIUM4.3Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access ...
CVE-2023-4958MEDIUM6.1In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowin...
CVE-2023-4932MEDIUM5.4SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` param...
CVE-2023-49713HIGH7.5Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacke...
CVE-2023-49143HIGH7.5Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker se...
CVE-2023-49140HIGH7.5Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated a...
CVE-2023-41963HIGH7.5Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker se...
CVE-2023-6547MEDIUM5.4Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions...
CVE-2023-49874MEDIUM4.3Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t...
CVE-2023-49809MEDIUM6.5Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul...
CVE-2023-49695MEDIUM6.8OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and...
CVE-2023-49607HIGH7.5Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playboo...
CVE-2023-49563MEDIUM6.1Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a craf...
CVE-2023-48677HIGH7.8Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2023-46701MEDIUM5.3Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint ...
CVE-2023-45847HIGH7.5Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now