2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28062 | HIGH | 8.8 | 0.8% | Apr 11, 2023 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated mal... |
| CVE-2023-26964 | HIGH | 7.5 | 1.1% | Apr 11, 2023 | An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE... |
| CVE-2023-27179 | HIGH | 7.5 | 60.8% | Apr 11, 2023 | GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet... |
| CVE-2023-26917 | HIGH | 7.5 | 0.9% | Apr 11, 2023 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat... |
| CVE-2023-1976 | HIGH | 8.8 | 0.6% | Apr 11, 2023 | Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-29054 | HIGH | 7.4 | 0.3% | Apr 11, 2023 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ... |
| CVE-2023-29053 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The ... |
| CVE-2023-28766 | HIGH | 7.5 | 0.9% | Apr 11, 2023 | A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300... |
| CVE-2023-26293 | HIGH | 7.3 | 0.2% | Apr 11, 2023 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int... |
| CVE-2023-27917 | HIGH | 8.8 | 1.9% | Apr 11, 2023 | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can acce... |
| CVE-2023-27389 | HIGH | 7.2 | 0.5% | Apr 11, 2023 | Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker wi... |
| CVE-2023-26593 | HIGH | 7.8 | 0.1% | Apr 11, 2023 | CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If... |
| CVE-2023-26588 | HIGH | 7.5 | 0.6% | Apr 11, 2023 | Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function o... |
| CVE-2023-25950 | HIGH | 7.3 | 2.9% | Apr 11, 2023 | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to a... |
| CVE-2023-25755 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the... |
| CVE-2023-24544 | HIGH | 8.1 | 0.3% | Apr 11, 2023 | Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific f... |
| CVE-2023-22429 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an extern... |
| CVE-2023-22282 | HIGH | 7.3 | 0.2% | Apr 11, 2023 | WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service pa... |
| CVE-2023-27267 | HIGH | 8.1 | 14.2% | Apr 11, 2023 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version... |
| CVE-2023-26458 | HIGH | 8.7 | 0.6% | Apr 11, 2023 | An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows ... |
| CVE-2023-27191 | HIGH | 7.5 | 1.1% | Apr 11, 2023 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPrefere... |
| CVE-2023-1668 | HIGH | 8.2 | 1.2% | Apr 10, 2023 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow ... |
| CVE-2023-29005 | HIGH | 7.5 | 0.6% | Apr 10, 2023 | Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. V... |
| CVE-2023-26466 | HIGH | 7.8 | 0.2% | Apr 10, 2023 | A user with non-Admin access can change a configuration file on the client to modify the Server URL. |
| CVE-2023-26495 | HIGH | 7.8 | 0.4% | Apr 10, 2023 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reus... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now