2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46096MEDIUM6.5A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does ...
CVE-2023-45794HIGH8.1A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications...
CVE-2023-44374HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM...
CVE-2023-44373CRITICAL9.4Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini...
CVE-2023-44322MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM...
CVE-2023-44321MEDIUM6.5Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web ...
CVE-2023-44320MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDC...
CVE-2023-44319MEDIUM4.9A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM...
CVE-2023-44318MEDIUM4.9Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the dev...
CVE-2023-44317HIGH8.6A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDC...
CVE-2023-43505MEDIUM6.5A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SM...
CVE-2023-43504CRITICAL9.8A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validat...
CVE-2023-43503HIGH7.5A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks ...
CVE-2023-31247CRITICAL9.8A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP...
CVE-2023-28391CRITICAL9.8A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.0...
CVE-2023-28379CRITICAL9.8A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01...
CVE-2023-27882CRITICAL9.8A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-H...
CVE-2023-25181CRITICAL9.8A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. ...
CVE-2023-24585CRITICAL9.8An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A spec...
CVE-2023-6109LOW3.7The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This i...
CVE-2023-47609HIGH8.8SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute ...
CVE-2023-45881MEDIUM6.1GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resu...
CVE-2023-45880HIGH7.2GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can crea...
CVE-2023-45879MEDIUM5.4GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.
CVE-2023-45878CRITICAL9.8GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now