2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48928MEDIUM6.1Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' par...
CVE-2023-26158HIGH8.2All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing che...
CVE-2023-48122HIGH7.5An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTT...
CVE-2023-43305HIGH8.2An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of...
CVE-2023-43744HIGH7.2An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware version...
CVE-2023-43743HIGH8.8A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior ...
CVE-2023-43742CRITICAL9.8An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17...
CVE-2023-6599MEDIUM4.3Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-6061Rejected reason: This CVE ID has been rejected/withdrawn by its CVE Numbering Authority (Palo Alto Networks) based on di...
CVE-2023-5008CRITICAL9.8Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter...
CVE-2023-5058HIGH7.8Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Tec...
CVE-2023-4122HIGH8.8Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-pr...
CVE-2023-6581CRITICAL9.8A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects ...
CVE-2023-6580HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part...
CVE-2023-6579CRITICAL9.8A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknow...
CVE-2023-46693MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title param...
CVE-2023-6578MEDIUM6.5A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown ...
CVE-2023-6577MEDIUM4.3A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affe...
CVE-2023-6576HIGH8.8A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects un...
CVE-2023-38174MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-36880MEDIUM4.8Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-35618CRITICAL9.6Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-6575HIGH8.8A vulnerability was found in Byzoro S210 up to 20231121. It has been classified as critical. This affects an unknown par...
CVE-2023-6574HIGH8.8A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some ...
CVE-2023-4486HIGH7.5Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now