2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47364MEDIUM6.5The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications ...
CVE-2023-47363MEDIUM6.5The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications...
CVE-2023-6052CRITICAL9.8A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.9. Affected is an unknown function of t...
CVE-2023-47616MEDIUM4.6A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli...
CVE-2023-47615MEDIUM5.5A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS...
CVE-2023-47612MEDIUM6.1A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinte...
CVE-2023-4218MEDIUM5In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE atta...
CVE-2023-47248CRITICAL9.8Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code ...
CVE-2023-47613HIGH7.1A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterio...
CVE-2023-47489HIGH7.8CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a c...
CVE-2023-47488MEDIUM6.1Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive informati...
CVE-2023-46492MEDIUM6.1Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a cr...
CVE-2023-26156HIGH7.5Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.pa...
CVE-2023-47008Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-47007Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-47006Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-47005Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-20902MEDIUM6.5A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and be...
CVE-2023-37790MEDIUM5.4Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profi...
CVE-2023-37533MEDIUM6.1HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to exe...
CVE-2023-4249CRITICAL9.8Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmw...
CVE-2023-45225CRITICAL9.8Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras  with firmwa...
CVE-2023-45079MEDIUM6.7A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated pr...
CVE-2023-45078MEDIUM6.7A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with el...
CVE-2023-45077MEDIUM6.7A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated pri...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now