2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47610CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow ...
CVE-2023-45885MEDIUM5.4Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary ...
CVE-2023-45884MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view se...
CVE-2023-45284MEDIUM5.3On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed ...
CVE-2023-45283HIGH7.5The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a...
CVE-2023-47110MEDIUM5.3blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store ...
CVE-2023-46894HIGH7.5An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
CVE-2023-46743MEDIUM4.3application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on...
CVE-2023-36688MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versio...
CVE-2023-25994HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.
CVE-2023-6039MEDIUM5.5A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb...
CVE-2023-47373MEDIUM6.5The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications...
CVE-2023-47372MEDIUM6.5The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifi...
CVE-2023-47370MEDIUM6.5The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to ...
CVE-2023-47368MEDIUM6.5The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications ...
CVE-2023-43791HIGH8.8Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability...
CVE-2023-41138MEDIUM6.7The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissio...
CVE-2023-41137CRITICAL9.8Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engine...
CVE-2023-40055HIGH8.8The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu...
CVE-2023-40054HIGH8.8The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu...
CVE-2023-4612CRITICAL9.8Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allo...
CVE-2023-47369MEDIUM6.5The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifi...
CVE-2023-47367MEDIUM6.5The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notificatio...
CVE-2023-47366MEDIUM6.5The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications...
CVE-2023-47365MEDIUM6.5The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notific...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now