2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-28062HIGH8.8 Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated mal...
CVE-2023-26964HIGH7.5An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE...
CVE-2023-27179HIGH7.5GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet...
CVE-2023-26917HIGH7.5libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat...
CVE-2023-1976HIGH8.8Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-29054HIGH7.4A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ...
CVE-2023-29053HIGH7.8A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The ...
CVE-2023-28766HIGH7.5A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300...
CVE-2023-26293HIGH7.3A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int...
CVE-2023-27917HIGH8.8OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can acce...
CVE-2023-27389HIGH7.2Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker wi...
CVE-2023-26593HIGH7.8CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If...
CVE-2023-26588HIGH7.5Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function o...
CVE-2023-25950HIGH7.3HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to a...
CVE-2023-25755HIGH7.8Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the...
CVE-2023-24544HIGH8.1Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific f...
CVE-2023-22429HIGH7.8Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an extern...
CVE-2023-22282HIGH7.3WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service pa...
CVE-2023-27267HIGH8.1Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version...
CVE-2023-26458HIGH8.7An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows ...
CVE-2023-27191HIGH7.5An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPrefere...
CVE-2023-1668HIGH8.2A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow ...
CVE-2023-29005HIGH7.5Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. V...
CVE-2023-26466HIGH7.8A user with non-Admin access can change a configuration file on the client to modify the Server URL.
CVE-2023-26495HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reus...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now