2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40182MEDIUM5.3Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticea...
CVE-2023-40179MEDIUM5.3Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Re...
CVE-2023-38974MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to exe...
CVE-2023-38973MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute a...
CVE-2023-39700MEDIUM6.1IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color...
CVE-2023-39699CRITICAL9.8IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /cale...
CVE-2023-4508MEDIUM5.5A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-ser...
CVE-2023-40030MEDIUM6.1Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo...
CVE-2023-40022HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to ...
CVE-2023-40017HIGH7.5GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In ...
CVE-2023-39521MEDIUM4.8Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi...
CVE-2023-39519MEDIUM4.9Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive in...
CVE-2023-38508MEDIUM4.3Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi...
CVE-2023-37469HIGH8.8CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to...
CVE-2023-32079HIGH8.8Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6...
CVE-2023-32078HIGH7.5Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions p...
CVE-2023-32077HIGH7.5Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in N...
CVE-2023-39801MEDIUM4.6A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to ...
CVE-2023-4420HIGH7.4A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo...
CVE-2023-4419HIGH8.8The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure...
CVE-2023-4418HIGH7.5A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-ba...
CVE-2023-31412HIGH7.5The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to ret...
CVE-2023-40904CRITICAL9.8Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and p...
CVE-2023-40902CRITICAL9.8Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at...
CVE-2023-40901CRITICAL9.8Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now