2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22580 | HIGH | 7.5 | 0.6% | Feb 16, 2023 | Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclos... |
| CVE-2023-22579 | HIGH | 8.8 | 0.8% | Feb 16, 2023 | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. |
| CVE-2023-0862 | HIGH | 8.8 | 2.4% | Feb 16, 2023 | The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file upl... |
| CVE-2023-0860 | HIGH | 7.5 | 0.7% | Feb 16, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. |
| CVE-2023-0861 | HIGH | 8.8 | 28.7% | Feb 16, 2023 | NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful... |
| CVE-2023-0662 | HIGH | 7.5 | 1.4% | Feb 16, 2023 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload ca... |
| CVE-2023-0568 | HIGH | 8.1 | 1.2% | Feb 16, 2023 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer on... |
| CVE-2023-0850 | HIGH | 7.5 | 1.0% | Feb 15, 2023 | A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown ... |
| CVE-2023-0848 | HIGH | 7.5 | 0.9% | Feb 15, 2023 | A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unkn... |
| CVE-2023-24498 | HIGH | 7.5 | 0.6% | Feb 15, 2023 | An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow d... |
| CVE-2023-23836 | HIGH | 7.2 | 80.3% | Feb 15, 2023 | SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerab... |
| CVE-2023-23466 | HIGH | 7.5 | 0.4% | Feb 15, 2023 | Media CP Media Control Panel latest version. Insufficiently protected credential change. |
| CVE-2023-23465 | HIGH | 8.8 | 0.3% | Feb 15, 2023 | Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. |
| CVE-2023-23464 | HIGH | 7.5 | 0.5% | Feb 15, 2023 | Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure. |
| CVE-2023-23463 | HIGH | 7.5 | 0.5% | Feb 15, 2023 | Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request... |
| CVE-2023-22806 | HIGH | 7.5 | 0.4% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicatin... |
| CVE-2023-22803 | HIGH | 7.5 | 0.6% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the... |
| CVE-2023-0361 | HIGH | 7.4 | 1.4% | Feb 15, 2023 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can ... |
| CVE-2023-0103 | HIGH | 7.5 | 0.7% | Feb 15, 2023 | If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are out... |
| CVE-2023-25578 | HIGH | 7.5 | 1.0% | Feb 15, 2023 | Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing ... |
| CVE-2023-25191 | HIGH | 7.5 | 0.6% | Feb 15, 2023 | AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-... |
| CVE-2023-25767 | HIGH | 8.8 | 0.5% | Feb 15, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allo... |
| CVE-2023-0841 | HIGH | 8.8 | 1.2% | Feb 15, 2023 | A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects t... |
| CVE-2023-25011 | HIGH | 7.8 | 0.2% | Feb 15, 2023 | PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the r... |
| CVE-2023-20927 | HIGH | 7.8 | 0.1% | Feb 15, 2023 | In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypas... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now