2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31808HIGH7.2Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative p...
CVE-2023-4092CRITICAL9.8SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow...
CVE-2023-41834MEDIUM6.1Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allo...
CVE-2023-23957MEDIUM5.4An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
CVE-2023-32649HIGH7.5A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain...
CVE-2023-2567HIGH8.8A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in ce...
CVE-2023-29245HIGH7.4A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields us...
CVE-2023-32186HIGH7.5A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s s...
CVE-2023-32184HIGH7.8A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute...
CVE-2023-0773CRITICAL9.8The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based manageme...
CVE-2023-41387CRITICAL9.1A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session toke...
CVE-2023-5009CRITICAL9.8An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions startin...
CVE-2023-5054MEDIUM5.3The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi...
CVE-2023-26143CRITICAL9.1Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. Th...
CVE-2023-42399MEDIUM6.1Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensiti...
CVE-2023-5060MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
CVE-2023-41599MEDIUM5.3An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traver...
CVE-2023-40788MEDIUM5.3SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway res...
CVE-2023-42454CRITICAL9.1SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed ...
CVE-2023-42446MEDIUM6.5Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and pri...
CVE-2023-41443HIGH7.2SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted scrip...
CVE-2023-39056MEDIUM6.5An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted message...
CVE-2023-39049MEDIUM6.5An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted mes...
CVE-2023-39046MEDIUM6.5An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send craf...
CVE-2023-37611MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now