2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33744 | CRITICAL | 9.8 | 0.8% | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. |
| CVE-2023-33743 | CRITICAL | 9.8 | 0.9% | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge ... |
| CVE-2023-33742 | HIGH | 7.5 | 0.5% | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in U... |
| CVE-2023-23764 | HIGH | 7.1 | 0.5% | Jul 27, 2023 | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa... |
| CVE-2023-36942 | MEDIUM | 6.1 | 0.5% | Jul 27, 2023 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows att... |
| CVE-2023-3982 | MEDIUM | 4.8 | 0.4% | Jul 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. |
| CVE-2023-3981 | MEDIUM | 4.9 | 0.6% | Jul 27, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2. |
| CVE-2023-3980 | MEDIUM | 4.8 | 0.4% | Jul 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. |
| CVE-2023-38510 | HIGH | 8.1 | 0.5% | Jul 27, 2023 | Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request i... |
| CVE-2023-38505 | HIGH | 7.5 | 0.7% | Jul 27, 2023 | DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to ... |
| CVE-2023-38504 | HIGH | 7.5 | 0.8% | Jul 27, 2023 | Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual req... |
| CVE-2023-38495 | CRITICAL | 9.8 | 0.7% | Jul 27, 2023 | Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1... |
| CVE-2023-36941 | MEDIUM | 6.1 | 0.5% | Jul 27, 2023 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows att... |
| CVE-2023-38492 | HIGH | 7.5 | 1.0% | Jul 27, 2023 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6... |
| CVE-2023-38491 | MEDIUM | 5.4 | 0.6% | Jul 27, 2023 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6... |
| CVE-2023-37900 | LOW | 2.7 | 0.5% | Jul 27, 2023 | Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1... |
| CVE-2023-29845 | — | — | — | Jul 27, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2023-3975 | CRITICAL | 9.8 | 1.9% | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. |
| CVE-2023-3974 | CRITICAL | 9.8 | 1.1% | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. |
| CVE-2023-3973 | MEDIUM | 6.1 | 0.3% | Jul 27, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3. |
| CVE-2023-38490 | CRITICAL | 10 | 1.5% | Jul 27, 2023 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6... |
| CVE-2023-38489 | HIGH | 7.3 | 0.7% | Jul 27, 2023 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6... |
| CVE-2023-38488 | HIGH | 8.8 | 0.8% | Jul 27, 2023 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6... |
| CVE-2023-37979 | MEDIUM | 6.1 | 6.0% | Jul 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 v... |
| CVE-2023-37977 | MEDIUM | 6.1 | 0.3% | Jul 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPr... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now