2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30952MEDIUM4.3A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the...
CVE-2023-30951MEDIUM6.5The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
CVE-2023-30950MEDIUM5.9The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
CVE-2023-20218MEDIUM6.1A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an...
CVE-2023-20216HIGH7.8A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica...
CVE-2023-20215MEDIUM5.3A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthen...
CVE-2023-20214CRITICAL9.1A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a...
CVE-2023-20204MEDIUM5.4A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ...
CVE-2023-20181MEDIUM6.1A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an una...
CVE-2023-3749MEDIUM5.5A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
CVE-2023-39121HIGH7.2emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
CVE-2023-33666CRITICAL9.8ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /...
CVE-2023-38942CRITICAL9.8Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/c...
CVE-2023-0956HIGH7.5 External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without ...
CVE-2023-39075MEDIUM4.6Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) a...
CVE-2023-36217CRITICAL9Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the cate...
CVE-2023-35081HIGH7.2A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) a...
CVE-2023-32764HIGH7.8Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
CVE-2023-4145MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
CVE-2023-36213CRITICAL9.8SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of ...
CVE-2023-25524MEDIUM5.3 NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where ...
CVE-2023-38948HIGH7.2An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers t...
CVE-2023-38947HIGH7.2An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to ex...
CVE-2023-33366HIGH8.8A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbit...
CVE-2023-33365HIGH7.5A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now