2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-27922MEDIUM6.1Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inj...
CVE-2023-27921MEDIUM6.5JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired b...
CVE-2023-27920MEDIUM4.3Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions pr...
CVE-2023-27384MEDIUM4.3Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker...
CVE-2023-27304MEDIUM4.3Operation restriction bypass vulnerability in Message and Bulletin of Cybozu Garoon 4.6.0 to 5.9.2 allows a remote authe...
CVE-2023-26595MEDIUM6.5Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker...
CVE-2023-23545MEDIUM5.3Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which m...
CVE-2023-22654MEDIUM5.4Client-side enforcement of server-side security issue exists in T&D Corporation and ESPEC MIC CORP. data logger products...
CVE-2023-31995MEDIUM5.4Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-31994MEDIUM5.3Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the...
CVE-2023-31708MEDIUM4.3A Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a c...
CVE-2023-31664MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2....
CVE-2023-25440MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe...
CVE-2023-31816MEDIUM6.1IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scri...
CVE-2023-31245MEDIUM6.1 Devices using Snap One OvrC cloud are sent to a web address when accessing a web management int...
CVE-2023-28412MEDIUM5.3 When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. ...
CVE-2023-31584MEDIUM6.1GitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerabilit...
CVE-2023-28467MEDIUM6.1In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
CVE-2023-2837MEDIUM5.5Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
CVE-2023-27066MEDIUM6.5Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attacker...
CVE-2023-33293MEDIUM5.3An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localh...
CVE-2023-32348MEDIUM5.8 Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for c...
CVE-2023-31101MEDIUM6.5Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects...
CVE-2023-32346MEDIUM5.3 Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devic...
CVE-2023-31779MEDIUM5.4Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now