2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42443HIGH8.1Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under ce...
CVE-2023-42441MEDIUM5.3Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior ...
CVE-2023-39452HIGH7.5 The web application that owns the device clearly stores the credentials within the user management sectio...
CVE-2023-39446HIGH8.8 Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the ...
CVE-2023-39058MEDIUM6.5An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted m...
CVE-2023-39043MEDIUM6.5An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and sen...
CVE-2023-39040MEDIUM6.5An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted mes...
CVE-2023-39039MEDIUM6.5An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send craf...
CVE-2023-38582MEDIUM5.4 Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote a...
CVE-2023-38255MEDIUM6.1 A potential attacker with or without (cookie theft) access to the device would be able to include malic...
CVE-2023-41965HIGH7.5Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack ...
CVE-2023-41084CRITICAL9.8 Session management within the web application is incorrect and allows attackers to steal session cookies to p...
CVE-2023-40221HIGH8.8 The absence of filters when loading some sections in the web application of the vulnerable device allows po...
CVE-2023-33831CRITICAL9.8A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute...
CVE-2023-41030CRITICAL9.8Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to t...
CVE-2023-4806MEDIUM5.9A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has...
CVE-2023-4527MEDIUM6.5A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is c...
CVE-2023-42328HIGH8.8An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and ex...
CVE-2023-42320CRITICAL9.8Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a ...
CVE-2023-41595HIGH7.5An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
CVE-2023-42387HIGH7.5An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via g...
CVE-2023-42371MEDIUM5.4Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execut...
CVE-2023-34195HIGH7.8An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The imple...
CVE-2023-32187HIGH7.5An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s se...
CVE-2023-42359CRITICAL9.8SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now