2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6274CRITICAL9.8A vulnerability was found in Byzoro Smart S80 up to 20231108. It has been declared as critical. Affected by this vulnera...
CVE-2023-46575CRITICAL9.8A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensit...
CVE-2023-38914Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-6251LOW3.5Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to dele...
CVE-2023-48796HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information ex...
CVE-2023-44303HIGH7.5 RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (R...
CVE-2023-33706MEDIUM6.5SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter t...
CVE-2023-26279HIGH7.8 IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to imprope...
CVE-2023-49216MEDIUM5.4Usedesk before 1.7.57 allows profile stored XSS.
CVE-2023-49215MEDIUM6.1Usedesk before 1.7.57 allows filter reflected XSS.
CVE-2023-49214CRITICAL9.8Usedesk before 1.7.57 allows chat template injection.
CVE-2023-49213HIGH8.8The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary comman...
CVE-2023-47529HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collect...
CVE-2023-47244HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by ...
CVE-2023-49210CRITICAL9.8The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" ...
CVE-2023-5972HIGH7.8A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue ...
CVE-2023-49208CRITICAL9.8scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation...
CVE-2023-33202MEDIUM5.5Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bounc...
CVE-2023-6118HIGH7.5Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal. This issue affects IP ...
CVE-2023-4677CRITICAL9.8Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Co...
CVE-2023-41812HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not P...
CVE-2023-41811MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all...
CVE-2023-41810MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all...
CVE-2023-41808HIGH7.5Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows...
CVE-2023-41807HIGH8.8Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now