2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-45209HIGH7.5An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplin...
CVE-2023-43491HIGH7.5An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Sma...
CVE-2023-39367HIGH7.2An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 ...
CVE-2023-51500HIGH7.7Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8.
CVE-2023-51418HIGH7.7Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: fr...
CVE-2023-52642HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rc: bpf attach/detach requires write permiss...
CVE-2023-44227HIGH7.5Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a th...
CVE-2023-36505HIGH7.2Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contac...
CVE-2023-51391HIGH7.5A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially al...
CVE-2023-50872HIGH7.5The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses...
CVE-2023-33806HIGH7.8Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to exe...
CVE-2023-4857HIGH7.5 An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to exe...
CVE-2023-4856HIGH8.8 A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbi...
CVE-2023-4855HIGH7.2 A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat...
CVE-2023-48709HIGH8iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' ...
CVE-2023-51515HIGH8.8Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: fr...
CVE-2023-49528HIGH8Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code an...
CVE-2023-44857HIGH8.1An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to ...
CVE-2023-44852HIGH8.2Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-5394HIGH7.4Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overfl...
CVE-2023-5393HIGH7.4Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in po...
CVE-2023-5392HIGH7.5C300 information leak due to an analysis feature which allows extracting more memory over the network than required by t...
CVE-2023-50949HIGH8.1IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validat...
CVE-2023-29483HIGH7eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution...
CVE-2023-6811HIGH7.2The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripti...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now