2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-22580HIGH7.5Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclos...
CVE-2023-22579HIGH8.8Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
CVE-2023-0862HIGH8.8The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file upl...
CVE-2023-0860HIGH7.5Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
CVE-2023-0861HIGH8.8NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful...
CVE-2023-0662HIGH7.5In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload ca...
CVE-2023-0568HIGH8.1In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer on...
CVE-2023-0850HIGH7.5A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown ...
CVE-2023-0848HIGH7.5A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unkn...
CVE-2023-24498HIGH7.5An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow d...
CVE-2023-23836HIGH7.2SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerab...
CVE-2023-23466HIGH7.5Media CP Media Control Panel latest version. Insufficiently protected credential change.
CVE-2023-23465HIGH8.8Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
CVE-2023-23464HIGH7.5Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
CVE-2023-23463HIGH7.5Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request...
CVE-2023-22806HIGH7.5LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicatin...
CVE-2023-22803HIGH7.5LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the...
CVE-2023-0361HIGH7.4A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can ...
CVE-2023-0103HIGH7.5If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are out...
CVE-2023-25578HIGH7.5Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing ...
CVE-2023-25191HIGH7.5AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-...
CVE-2023-25767HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allo...
CVE-2023-0841HIGH8.8A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects t...
CVE-2023-25011HIGH7.8PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the r...
CVE-2023-20927HIGH7.8In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypas...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now