2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49052 | HIGH | 8.8 | 2.4% | Nov 30, 2023 | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script ... |
| CVE-2023-49087 | HIGH | 7.5 | 0.2% | Nov 30, 2023 | xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verific... |
| CVE-2023-49076 | MEDIUM | 6.5 | 0.3% | Nov 30, 2023 | Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSR... |
| CVE-2023-47418 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface i... |
| CVE-2023-5275 | MEDIUM | 4.7 | 0.3% | Nov 30, 2023 | Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv... |
| CVE-2023-5274 | MEDIUM | 4.7 | 0.3% | Nov 30, 2023 | Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv... |
| CVE-2023-49097 | HIGH | 8.8 | 0.8% | Nov 30, 2023 | ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded... |
| CVE-2023-49094 | MEDIUM | 4.3 | 0.7% | Nov 30, 2023 | Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker cou... |
| CVE-2023-47464 | HIGH | 8.8 | 22.6% | Nov 30, 2023 | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi... |
| CVE-2023-47463 | CRITICAL | 9.8 | 1.3% | Nov 30, 2023 | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi... |
| CVE-2023-5772 | MEDIUM | 4.3 | 0.3% | Nov 30, 2023 | The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2023-5247 | HIGH | 7.8 | 0.3% | Nov 30, 2023 | Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA E... |
| CVE-2023-4474 | CRITICAL | 9.8 | 29.7% | Nov 30, 2023 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0... |
| CVE-2023-4473 | CRITICAL | 9.8 | 41.3% | Nov 30, 2023 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fir... |
| CVE-2023-37928 | HIGH | 8.8 | 60.2% | Nov 30, 2023 | A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF... |
| CVE-2023-37927 | HIGH | 8.8 | 1.8% | Nov 30, 2023 | The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0... |
| CVE-2023-35138 | CRITICAL | 9.8 | 40.0% | Nov 30, 2023 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.... |
| CVE-2023-35137 | HIGH | 7.5 | 0.9% | Nov 30, 2023 | An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14... |
| CVE-2023-3741 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execut... |
| CVE-2023-49694 | HIGH | 7.8 | 0.5% | Nov 29, 2023 | A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed c... |
| CVE-2023-49693 | CRITICAL | 9.8 | 1.2% | Nov 29, 2023 | NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotel... |
| CVE-2023-40458 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially all... |
| CVE-2023-49091 | CRITICAL | 9.8 | 0.8% | Nov 29, 2023 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ... |
| CVE-2023-49082 | MEDIUM | 5.3 | 0.9% | Nov 29, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo... |
| CVE-2023-48952 | HIGH | 7.5 | 1.0% | Nov 29, 2023 | An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now