2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6508HIGH8.8Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit ...
CVE-2023-48940MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary ...
CVE-2023-48930CRITICAL9.8xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
CVE-2023-28876MEDIUM4.3A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delet...
CVE-2023-28875MEDIUM5.4A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code ...
CVE-2023-24547MEDIUM6.5On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in cl...
CVE-2023-49283MEDIUM5.3microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which cont...
CVE-2023-49282MEDIUM5.3msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained t...
CVE-2023-5970HIGH8.8Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an ...
CVE-2023-49297HIGH7.8PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe ...
CVE-2023-46736MEDIUM6.5EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Req...
CVE-2023-44221HIGH7.2Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated att...
CVE-2023-6448CRITICAL9.8Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative passwo...
CVE-2023-46674HIGH7.8An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration prope...
CVE-2023-45287HIGH7.5Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was ...
CVE-2023-45085LOW3.3An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct ini...
CVE-2023-45084MEDIUM6.1An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause ...
CVE-2023-45083MEDIUM4.4An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authentic...
CVE-2023-44298MEDIUM6.8 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v...
CVE-2023-44297MEDIUM6.8 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v...
CVE-2023-6357HIGH8.8A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system l...
CVE-2023-6180MEDIUM5.3The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consump...
CVE-2023-49448HIGH8.8JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
CVE-2023-49447HIGH8.8JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
CVE-2023-49446HIGH8.8JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now