2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5365CRITICAL9.8HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
CVE-2023-44400HIGH7.8Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain...
CVE-2023-41047MEDIUM6.5OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability th...
CVE-2023-30910MEDIUM5.4HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP r...
CVE-2023-44393MEDIUM6.1Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS)...
CVE-2023-44378MEDIUM5.5gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit...
CVE-2023-43643MEDIUM6.1AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to versio...
CVE-2023-41660HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WPSynchro WP Synchro plugin <= 1.9.1 versions.
CVE-2023-36820MEDIUM6.5Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, ...
CVE-2023-25822MEDIUM6.5ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-ap...
CVE-2023-5103MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to pot...
CVE-2023-5102MEDIUM5.3 Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable...
CVE-2023-5101MEDIUM5.3 Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to dow...
CVE-2023-5100MEDIUM6.5 Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retriev...
CVE-2023-43698MEDIUM6.1 Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an un...
CVE-2023-43697MEDIUM6.5 Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the ...
CVE-2023-45248HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2023-45247HIGH7.1Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr...
CVE-2023-43700HIGH7.5Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that...
CVE-2023-43699HIGH7.5 Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker ...
CVE-2023-43696CRITICAL9.8 Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file...
CVE-2023-5333MEDIUM6.5Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources...
CVE-2023-5331MEDIUM5.3Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exp...
CVE-2023-5330HIGH7.5Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s...
CVE-2023-45613CRITICAL9.1In JetBrains Ktor before 2.3.5 server certificates were not verified

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now