2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49052HIGH8.8File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script ...
CVE-2023-49087HIGH7.5xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verific...
CVE-2023-49076MEDIUM6.5Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSR...
CVE-2023-47418CRITICAL9.8Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface i...
CVE-2023-5275MEDIUM4.7Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv...
CVE-2023-5274MEDIUM4.7Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv...
CVE-2023-49097HIGH8.8ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded...
CVE-2023-49094MEDIUM4.3Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker cou...
CVE-2023-47464HIGH8.8Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi...
CVE-2023-47463CRITICAL9.8Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi...
CVE-2023-5772MEDIUM4.3The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2023-5247HIGH7.8Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA E...
CVE-2023-4474CRITICAL9.8The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0...
CVE-2023-4473CRITICAL9.8A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fir...
CVE-2023-37928HIGH8.8A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF...
CVE-2023-37927HIGH8.8The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0...
CVE-2023-35138CRITICAL9.8A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5....
CVE-2023-35137HIGH7.5An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14...
CVE-2023-3741CRITICAL9.8An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execut...
CVE-2023-49694HIGH7.8 A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed c...
CVE-2023-49693CRITICAL9.8 NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotel...
CVE-2023-40458HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially all...
CVE-2023-49091CRITICAL9.8Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ...
CVE-2023-49082MEDIUM5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo...
CVE-2023-48952HIGH7.5An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now