2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38700LOW3.7matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such...
CVE-2023-4159HIGH8.8Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.
CVE-2023-4158MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3.
CVE-2023-4157MEDIUM4.8CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repo...
CVE-2023-39107CRITICAL9.1An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows...
CVE-2023-38699MEDIUM6.5MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0,...
CVE-2023-38698MEDIUM6.5Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. Accor...
CVE-2023-38697MEDIUM5.3protocol-http1 provides a low-level implementation of the HTTP/1 protocol. RFC 9112 Section 7.1 defined the format of ch...
CVE-2023-38695MEDIUM6.5cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possib...
CVE-2023-38692CRITICAL9.8CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command i...
CVE-2023-38332MEDIUM6.5Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitiv...
CVE-2023-33379CRITICAL9.8Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, ...
CVE-2023-33378CRITICAL9.8Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro...
CVE-2023-33377CRITICAL9.8Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its commu...
CVE-2023-33376CRITICAL9.8Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati...
CVE-2023-33375CRITICAL9.8Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling at...
CVE-2023-33374CRITICAL9.8Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to sp...
CVE-2023-33373CRITICAL9.8Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the...
CVE-2023-33372CRITICAL9.8Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi...
CVE-2023-0264MEDIUM5A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authen...
CVE-2023-39143CRITICAL9.8PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete...
CVE-2023-39112MEDIUM6.5ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
CVE-2023-38691MEDIUM6.5matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 a...
CVE-2023-38690CRITICAL9.8matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with...
CVE-2023-38689CRITICAL9.8Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `Object...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now