2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43902CRITICAL9.8Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attacker...
CVE-2023-43901HIGH7.5Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to ...
CVE-2023-43900MEDIUM6.5Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized a...
CVE-2023-42326HIGH8.8An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the inte...
CVE-2023-6006MEDIUM6.7This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. A...
CVE-2023-42327MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr...
CVE-2023-42325MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr...
CVE-2023-31754MEDIUM4.8Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin pan...
CVE-2023-46446MEDIUM6.8An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet inject...
CVE-2023-46445MEDIUM5.9An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-mi...
CVE-2023-45560HIGH7.5An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel acce...
CVE-2023-45558HIGH7.5An issue in Golden v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
CVE-2023-47629HIGH8DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restr...
CVE-2023-47628MEDIUM4.8DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default s...
CVE-2023-42480MEDIUM5.3The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functional...
CVE-2023-41366MEDIUM5.3Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7....
CVE-2023-31403HIGH8SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB sh...
CVE-2023-6115Rejected reason: DUPLICATE CVE
CVE-2023-6107Rejected reason: Accidental Request.
CVE-2023-6106Rejected reason: Accidental request.
CVE-2023-6092Rejected reason: DUPLICATE, accidental request.
CVE-2023-6089Rejected reason: Accidental Request.
CVE-2023-6088Rejected reason: Accidental Request.
CVE-2023-6087Rejected reason: Accidental Request.
CVE-2023-6086Rejected reason: Accidental request.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now