2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41806HIGH7.5Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes...
CVE-2023-41792MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerabil...
CVE-2023-41791MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all...
CVE-2023-41790CRITICAL9.8Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File S...
CVE-2023-41789MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all...
CVE-2023-41788HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not P...
CVE-2023-41787HIGH7.5Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File S...
CVE-2023-41786MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. Th...
CVE-2023-4595MEDIUM6.5An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve se...
CVE-2023-4594MEDIUM5.4Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and...
CVE-2023-4593MEDIUM6.5Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's int...
CVE-2023-4406MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerc...
CVE-2023-43123MEDIUM5.5On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs ...
CVE-2023-3631CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Medart Health Serv...
CVE-2023-3377CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veribilim Software...
CVE-2023-28813HIGH7.5An attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in to modify...
CVE-2023-28812CRITICAL9.8There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability b...
CVE-2023-44290HIGH7.8 Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious s...
CVE-2023-44289HIGH7.8 Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious ...
CVE-2023-43086HIGH7.8 Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local maliciou...
CVE-2023-39253HIGH7.8 Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. ...
CVE-2023-28811MEDIUM6.5There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on th...
CVE-2023-41140HIGH7.8A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buff...
CVE-2023-41139HIGH7.8A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untruste...
CVE-2023-29076CRITICAL9.8A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now