2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41775MEDIUM5.5Improper access control vulnerability in 'direct' Desktop App for macOS ver 2.6.0 and earlier allows a local attacker to...
CVE-2023-34041MEDIUM5.3Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthent...
CVE-2023-32470MEDIUM5.5 Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulner...
CVE-2023-41615CRITICAL9.8Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page vi...
CVE-2023-41594HIGH7.5Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilit...
CVE-2023-40953HIGH8.8icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-40353LOW3.3An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the e...
CVE-2023-39620HIGH7.5An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitiv...
CVE-2023-37759CRITICAL9.8Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat...
CVE-2023-37377HIGH7.5An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, ...
CVE-2023-37368HIGH7.5An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Au...
CVE-2023-37367MEDIUM5.3An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Ex...
CVE-2023-40271HIGH7.5In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell P...
CVE-2023-36184HIGH7.5CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.
CVE-2023-40584MEDIUM6.5Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug wher...
CVE-2023-40029CRITICAL9.6Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us...
CVE-2023-41646MEDIUM5.3Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the ...
CVE-2023-41161MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary w...
CVE-2023-30908CRITICAL9.8A remote authentication bypass issue exists in a OneView API.
CVE-2023-41316MEDIUM5.4Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi...
CVE-2023-20194MEDIUM4.9A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the...
CVE-2023-20193MEDIUM6.7A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, ...
CVE-2023-37798MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1....
CVE-2023-4685HIGH7.8Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffe...
CVE-2023-4528HIGH7.2Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now