2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5921HIGH7.1Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issu...
CVE-2023-2447MEDIUM6.1The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th...
CVE-2023-2446MEDIUM6.5The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio...
CVE-2023-47393MEDIUM5.3An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of othe...
CVE-2023-47392MEDIUM5.3An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via s...
CVE-2023-47016HIGH7.5radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in ...
CVE-2023-41146MEDIUM4.3Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on t...
CVE-2023-41145MEDIUM5.3Autodesk users who no longer have an active license for an account can still access cases for that account.
CVE-2023-29069HIGH7.8A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of...
CVE-2023-48161HIGH7.1Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information v...
CVE-2023-46814HIGH7.8A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller a...
CVE-2023-5299HIGH8.8A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.
CVE-2023-40152HIGH7.8When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur.
CVE-2023-35127HIGH7.8Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.
CVE-2023-48701MEDIUM6.1Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML file...
CVE-2023-48700MEDIUM6.5The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new ...
CVE-2023-48699CRITICAL9.8fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior ...
CVE-2023-48307CRITICAL9.8Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior ...
CVE-2023-48306CRITICAL9.8Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-48305MEDIUM4.4Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-6248CRITICAL9.8The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u...
CVE-2023-49105CRITICAL9.8An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit...
CVE-2023-49104MEDIUM6.1An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able ...
CVE-2023-49103HIGH7.5An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies...
CVE-2023-48304MEDIUM4.3Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now