2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44048MEDIUM5.4Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.
CVE-2023-44047HIGH7.2Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
CVE-2023-4523MEDIUM6.1 Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which co...
CVE-2023-43652CRITICAL9.1JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi...
CVE-2023-43650HIGH7.4JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-fo...
CVE-2023-33972HIGH8.8Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who ar...
CVE-2023-5184HIGH8.8Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the...
CVE-2023-42822MEDIUM6.5xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked...
CVE-2023-20268MEDIUM4.7A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticate...
CVE-2023-20262HIGH7.5A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to c...
CVE-2023-20254HIGH8.8A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow a...
CVE-2023-20253MEDIUM5.5A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenti...
CVE-2023-20252CRITICAL9.8A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al...
CVE-2023-20251MEDIUM5.3A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticat...
CVE-2023-20231HIGH8.8A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injec...
CVE-2023-20227HIGH7.5A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated...
CVE-2023-20226HIGH7.5A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software ...
CVE-2023-20223HIGH8.2A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a reposit...
CVE-2023-20202MEDIUM6.5A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers coul...
CVE-2023-20187HIGH7.5A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Ser...
CVE-2023-20186CRITICAL9.1A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS X...
CVE-2023-20179MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2023-20176HIGH8.6A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote a...
CVE-2023-20109MEDIUM6.6A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Soft...
CVE-2023-20034HIGH7.5Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now