2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33364HIGH8.8An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to exe...
CVE-2023-33363HIGH7.5An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to a...
CVE-2023-4138MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
CVE-2023-4136MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine ...
CVE-2023-4133MEDIUM5.5A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device i...
CVE-2023-4132MEDIUM5.5A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device in...
CVE-2023-3766MEDIUM5.9A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted qu...
CVE-2023-3348MEDIUM5.7The Wrangler command line tool  (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerabil...
CVE-2023-3180MEDIUM6.5A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_h...
CVE-2023-39097MEDIUM5.4WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.
CVE-2023-39096MEDIUM5.4WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and o...
CVE-2023-38812Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36299HIGH8.8A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and opt...
CVE-2023-36298HIGH8.8DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
CVE-2023-2754MEDIUM6.8The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS...
CVE-2023-28468MEDIUM6.5An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntime...
CVE-2023-25600HIGH7.1An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, lead...
CVE-2023-22277HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-22317HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-22314HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-3669LOW3.3A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimi...
CVE-2023-37559MEDIUM6.5After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co...
CVE-2023-37558MEDIUM6.5After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co...
CVE-2023-37557MEDIUM6.5After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote com...
CVE-2023-37556MEDIUM6.5In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now