2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50450HIGH8.4An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified acti...
CVE-2023-47295CRITICAL9.8A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injectin...
CVE-2023-47294HIGH8.1An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, l...
CVE-2023-47032CRITICAL9.8Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted ...
CVE-2023-48978CRITICAL9.8An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2023-47298MEDIUM4.3An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoi...
CVE-2023-47297CRITICAL9.8A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, inc...
CVE-2023-5600LOW3.1An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting...
CVE-2023-45256MEDIUM5.4Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow ...
CVE-2023-36636Rejected reason: Not used
CVE-2023-48786MEDIUM4.3A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before ...
CVE-2023-29184LOW2.3An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through...
CVE-2023-20599HIGH7.9Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto C...
CVE-2023-26005HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-25999HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-26003HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vipul Jariwala WP ...
CVE-2023-26002MEDIUM4.3Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control...
CVE-2023-26001MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design N...
CVE-2023-26000MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hanhdo205 Bang tin...
CVE-2023-25997MEDIUM6.5Missing Authorization vulnerability in SolaPlugins Sola Support Ticket allows Exploiting Incorrectly Configured Access C...
CVE-2023-25995HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-2921HIGH8.8The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL st...
CVE-2023-26226CRITICAL9.8A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
CVE-2023-41591CRITICAL9.8An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute...
CVE-2023-51756Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now