2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26151HIGH7.5Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a...
CVE-2023-26150HIGH7.5Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to acce...
CVE-2023-5345HIGH7.8A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege...
CVE-2023-5334MEDIUM5.4The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsi...
CVE-2023-3967HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows...
CVE-2023-3440HIGH7.8Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.Th...
CVE-2023-3335MEDIUM5.5Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local...
CVE-2023-43627MEDIUM5.7Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier...
CVE-2023-42771HIGH8.8Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and ...
CVE-2023-41086HIGH8.8Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user vi...
CVE-2023-39429MEDIUM5.4Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to i...
CVE-2023-39222HIGH8.8OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to e...
CVE-2023-36628HIGH8.8A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access ...
CVE-2023-32572MEDIUM4.9A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention l...
CVE-2023-28373LOW2.7A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the ...
CVE-2023-43980CRITICAL9.8Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component di...
CVE-2023-36627LOW2.7A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is confi...
CVE-2023-31042MEDIUM4.3A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can i...
CVE-2023-28372LOW2.7A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention per...
CVE-2023-44012MEDIUM6.1Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the he...
CVE-2023-44011CRITICAL9.8An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.m...
CVE-2023-43893CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the W...
CVE-2023-43892CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the...
CVE-2023-43891CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password...
CVE-2023-44009CRITICAL9.8File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Manage...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now