2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30952 | MEDIUM | 4.3 | 0.4% | Aug 3, 2023 | A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the... |
| CVE-2023-30951 | MEDIUM | 6.5 | 0.4% | Aug 3, 2023 | The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE). |
| CVE-2023-30950 | MEDIUM | 5.9 | 0.3% | Aug 3, 2023 | The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint |
| CVE-2023-20218 | MEDIUM | 6.1 | 0.4% | Aug 3, 2023 | A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an... |
| CVE-2023-20216 | HIGH | 7.8 | 0.1% | Aug 3, 2023 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica... |
| CVE-2023-20215 | MEDIUM | 5.3 | 0.5% | Aug 3, 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthen... |
| CVE-2023-20214 | CRITICAL | 9.1 | 0.7% | Aug 3, 2023 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a... |
| CVE-2023-20204 | MEDIUM | 5.4 | 0.4% | Aug 3, 2023 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ... |
| CVE-2023-20181 | MEDIUM | 6.1 | 0.4% | Aug 3, 2023 | A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an una... |
| CVE-2023-3749 | MEDIUM | 5.5 | 0.1% | Aug 3, 2023 | A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation. |
| CVE-2023-39121 | HIGH | 7.2 | 2.3% | Aug 3, 2023 | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. |
| CVE-2023-33666 | CRITICAL | 9.8 | 0.5% | Aug 3, 2023 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /... |
| CVE-2023-38942 | CRITICAL | 9.8 | 1.6% | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/c... |
| CVE-2023-0956 | HIGH | 7.5 | 0.8% | Aug 3, 2023 | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without ... |
| CVE-2023-39075 | MEDIUM | 4.6 | 0.4% | Aug 3, 2023 | Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) a... |
| CVE-2023-36217 | CRITICAL | 9 | 1.4% | Aug 3, 2023 | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the cate... |
| CVE-2023-35081 | HIGH | 7.2 | 63.3% | Aug 3, 2023 | A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) a... |
| CVE-2023-32764 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator. |
| CVE-2023-4145 | MEDIUM | 5.4 | 0.5% | Aug 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. |
| CVE-2023-36213 | CRITICAL | 9.8 | 1.1% | Aug 3, 2023 | SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of ... |
| CVE-2023-25524 | MEDIUM | 5.3 | 0.3% | Aug 3, 2023 | NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where ... |
| CVE-2023-38948 | HIGH | 7.2 | 0.9% | Aug 3, 2023 | An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers t... |
| CVE-2023-38947 | HIGH | 7.2 | 0.5% | Aug 3, 2023 | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to ex... |
| CVE-2023-33366 | HIGH | 8.8 | 0.6% | Aug 3, 2023 | A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbit... |
| CVE-2023-33365 | HIGH | 7.5 | 0.7% | Aug 3, 2023 | A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now