2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6206MEDIUM5.4The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prom...
CVE-2023-6205MEDIUM6.5It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to a...
CVE-2023-6204MEDIUM6.5On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak m...
CVE-2023-49061MEDIUM6.1An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerab...
CVE-2023-49060CRITICAL9.8An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrer...
CVE-2023-48124MEDIUM5.4Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email...
CVE-2023-6235HIGH7.8An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1....
CVE-2023-28802MEDIUM5.4An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to d...
CVE-2023-5599MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x thr...
CVE-2023-5598MEDIUM5.4Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ...
CVE-2023-5776HIGH8.8The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2023-5553MEDIUM6.8During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t...
CVE-2023-4424HIGH8.8An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, le...
CVE-2023-4149CRITICAL9.8A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system command...
CVE-2023-46935MEDIUM5.4eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in u...
CVE-2023-21418HIGH7.1Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to pat...
CVE-2023-21417HIGH7.1Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnera...
CVE-2023-21416MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable t...
CVE-2023-45886HIGH7.5The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending...
CVE-2023-42770CRITICAL9.8 Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an...
CVE-2023-6144MEDIUM4.8Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use...
CVE-2023-6142MEDIUM5.4Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. Wi...
CVE-2023-40151CRITICAL9.8 When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK ...
CVE-2023-6199MEDIUM6.5Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulne...
CVE-2023-48310HIGH7.5TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now