2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44486Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44485Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44484MEDIUM6.1Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstNam...
CVE-2023-46485CRITICAL9.8An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracero...
CVE-2023-46484CRITICAL9.8An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg ...
CVE-2023-43295LOW3.5Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a lo...
CVE-2023-3955HIGH8.8A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat...
CVE-2023-3676HIGH8.8A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat...
CVE-2023-39610MEDIUM6.5An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Ser...
CVE-2023-20886MEDIUM6.1VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a ...
CVE-2023-41377Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2023-45955HIGH7.5An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write bind...
CVE-2023-37832HIGH7.5A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute forc...
CVE-2023-37831MEDIUM5.3An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server re...
CVE-2023-43796MEDIUM5.3Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote ...
CVE-2023-5739HIGH7.8Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
CVE-2023-46723HIGH7.5lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable t...
CVE-2023-46722MEDIUM6.1The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulne...
CVE-2023-46256CRITICAL9.8PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a hea...
CVE-2023-46255MEDIUM6.5SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per...
CVE-2023-46250MEDIUM5.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 ...
CVE-2023-46249CRITICAL9.8authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has...
CVE-2023-46248HIGH8.8Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 ar...
CVE-2023-46245HIGH7.2Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Templ...
CVE-2023-46240HIGH7.5CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now