2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42491CRITICAL9.8EisBaer Scada - CWE-285: Improper Authorization
CVE-2023-42490HIGH7.5 EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2023-42489CRITICAL9.8 EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
CVE-2023-42488HIGH7.5 EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42031MEDIUM4.9IBM TXSeries for Multiplatforms, 8.1, 8.2, and 9.1, CICS TX Standard CICS TX Advanced 10.1 and 11.1 could allow a privil...
CVE-2023-41960LOW3.3The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely...
CVE-2023-41721MEDIUM5.3Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and e...
CVE-2023-41372HIGH7.8The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of...
CVE-2023-41339MEDIUM5.3GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS...
CVE-2023-41255HIGH8.8The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on t...
CVE-2023-3112HIGH7.8A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker wi...
CVE-2023-3010MEDIUM6.1Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 ...
CVE-2023-39930CRITICAL9.8A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authe...
CVE-2023-39924MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versi...
CVE-2023-39817Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-39816Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-39815Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-39814Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-39740HIGH8.2The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token an...
CVE-2023-39739HIGH8.2The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token...
CVE-2023-39737HIGH8.2The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send cra...
CVE-2023-39736HIGH8.2The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token...
CVE-2023-39735HIGH8.2The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token an...
CVE-2023-39734HIGH8.2The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the cha...
CVE-2023-39733HIGH8.2The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now