2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-31162MEDIUM4.3An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (S...
CVE-2023-31160MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31159MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31158MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31157MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31156MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31155MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31154MEDIUM5.4 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer...
CVE-2023-31153MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer ...
CVE-2023-31151MEDIUM4.2An Improper Certificate Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Contr...
CVE-2023-31150MEDIUM6.5 A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automati...
CVE-2023-2310MEDIUM5.3A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL Real-Time Automation C...
CVE-2023-32076MEDIUM5.5in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and...
CVE-2023-32070MEDIUM6.1XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attribu...
CVE-2023-0008MEDIUM4.4A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator ...
CVE-2023-0007MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authe...
CVE-2023-31556MEDIUM6.5podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyPare...
CVE-2023-31555MEDIUM6.5podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.
CVE-2023-2630MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-27562MEDIUM6.5The n8n package 0.218.0 for Node.js allows Directory Traversal.
CVE-2023-28411MEDIUM5.5Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable informa...
CVE-2023-25776MEDIUM4.4Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to ...
CVE-2023-25772MEDIUM5.5Improper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may a...
CVE-2023-25771MEDIUM5.5Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of ...
CVE-2023-25545MEDIUM6.7Improper buffer restrictions in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now