2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49243HIGH7.5Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerabi...
CVE-2023-49242HIGH7.5Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect ...
CVE-2023-49241HIGH7.5API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may...
CVE-2023-49240HIGH7.5Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect servi...
CVE-2023-49239HIGH7.5Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec...
CVE-2023-46773CRITICAL9.8Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege...
CVE-2023-46688MEDIUM6.1Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect user...
CVE-2023-45210MEDIUM4.3Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticate...
CVE-2023-44113HIGH7.5Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful explo...
CVE-2023-44099HIGH7.5Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause ...
CVE-2023-34439MEDIUM5.4Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited...
CVE-2023-48849CRITICAL9.8Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitr...
CVE-2023-49897HIGH8.8An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version ...
CVE-2023-2861HIGH7.1A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit openin...
CVE-2023-6527MEDIUM6.1The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER h...
CVE-2023-26154MEDIUM5.9Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubn...
CVE-2023-22524CRITICAL9.8Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att...
CVE-2023-22523HIGH8.8This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with ...
CVE-2023-22522HIGH8.8This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject u...
CVE-2023-41268CRITICAL9.8Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. Th...
CVE-2023-40053MEDIUM5A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file ...
CVE-2023-6512MEDIUM6.5Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to pote...
CVE-2023-6511MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Aut...
CVE-2023-6510HIGH8.8Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user t...
CVE-2023-6509HIGH8.8Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a us...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now