2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48401MEDIUM5.5In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check....
CVE-2023-48399MEDIUM5.5In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a miss...
CVE-2023-48398HIGH7.5In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds rea...
CVE-2023-48397MEDIUM4.9In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lea...
CVE-2023-47565HIGH8.8An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. ...
CVE-2023-32975HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-32968HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-23372MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2023-6611HIGH7.5A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unk...
CVE-2023-6609MEDIUM6.1A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi...
CVE-2023-6608HIGH7.5A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknow...
CVE-2023-6245HIGH7.5The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For exa...
CVE-2023-6146MEDIUM5.4 A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in th...
CVE-2023-49487MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management depar...
CVE-2023-49486MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department...
CVE-2023-49485MEDIUM5.4JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management departmen...
CVE-2023-49484MEDIUM5.4Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management depart...
CVE-2023-49444MEDIUM5.4An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a craft...
CVE-2023-49443CRITICAL9.8DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerabil...
CVE-2023-6607HIGH7.5A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability ...
CVE-2023-49007CRITICAL9.8In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.
CVE-2023-46157HIGH8.8File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by c...
CVE-2023-45866MEDIUM6.3Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encry...
CVE-2023-32460HIGH7.8 Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker...
CVE-2023-48929CRITICAL9.8Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now