2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41031HIGH8.8Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authentic...
CVE-2023-41029HIGH8.8Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1...
CVE-2023-41027HIGH8.8Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 an...
CVE-2023-42811MEDIUM5.5aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES...
CVE-2023-42798CRITICAL9.1AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1...
CVE-2023-43144CRITICAL9.8Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
CVE-2023-23766MEDIUM6.5An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa...
CVE-2023-5002HIGH8.8A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to ext...
CVE-2023-34319HIGH7.8The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that...
CVE-2023-4774MEDIUM5.4The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik...
CVE-2023-4716MEDIUM5.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor...
CVE-2023-43784HIGH7.5Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE...
CVE-2023-43783HIGH7.5Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if...
CVE-2023-43782MEDIUM5.5Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if ...
CVE-2023-43771MEDIUM5.5In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.
CVE-2023-43770MEDIUM6.1Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft...
CVE-2023-43090MEDIUM5.5A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows...
CVE-2023-43767HIGH7.5Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Clien...
CVE-2023-43766HIGH7.8Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure...
CVE-2023-43765HIGH7.5Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, ...
CVE-2023-43764Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-43762. Reason: This candidate is a duplicate of ...
CVE-2023-43763MEDIUM6.1Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manag...
CVE-2023-43762CRITICAL9.8Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithS...
CVE-2023-43761HIGH7.5Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSec...
CVE-2023-43760HIGH7.5Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now