2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39780HIGH8.8On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply...
CVE-2023-39070HIGH7.8An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in...
CVE-2023-39068HIGH7.5Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N...
CVE-2023-39063HIGH7.8Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server na...
CVE-2023-38829HIGH8.8An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and tracer...
CVE-2023-38743HIGH7.2Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
CVE-2023-31468HIGH7.8An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I...
CVE-2023-31069CRITICAL9.8An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s...
CVE-2023-31068CRITICAL9.8An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so...
CVE-2023-31067CRITICAL9.8An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so...
CVE-2023-41609MEDIUM6.1An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim us...
CVE-2023-41593MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow ...
CVE-2023-39067MEDIUM6.1Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a cra...
CVE-2023-4881Rejected reason: CVE-2023-4881 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux ker...
CVE-2023-30058CRITICAL9.8novel-plus 3.6.2 is vulnerable to SQL Injection.
CVE-2023-41000MEDIUM5.5GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder....
CVE-2023-36140CRITICAL9.8In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain acce...
CVE-2023-27470HIGH7BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a ps...
CVE-2023-4630MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting fr...
CVE-2023-40786MEDIUM5.4HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.
CVE-2023-36980MEDIUM5.3An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casin...
CVE-2023-36161HIGH7.5An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of ...
CVE-2023-3612HIGH8.8Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an U...
CVE-2023-4585HIGH8.8Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence ...
CVE-2023-4584HIGH8.8Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 11...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now