2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33744CRITICAL9.8TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
CVE-2023-33743CRITICAL9.8TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge ...
CVE-2023-33742HIGH7.5TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in U...
CVE-2023-23764HIGH7.1An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa...
CVE-2023-36942MEDIUM6.1A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows att...
CVE-2023-3982MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.
CVE-2023-3981MEDIUM4.9Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.
CVE-2023-3980MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.
CVE-2023-38510HIGH8.1Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request i...
CVE-2023-38505HIGH7.5DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to ...
CVE-2023-38504HIGH7.5Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual req...
CVE-2023-38495CRITICAL9.8Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1...
CVE-2023-36941MEDIUM6.1A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows att...
CVE-2023-38492HIGH7.5Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-38491MEDIUM5.4Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-37900LOW2.7Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1...
CVE-2023-29845Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-3975CRITICAL9.8OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
CVE-2023-3974CRITICAL9.8OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
CVE-2023-3973MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3.
CVE-2023-38490CRITICAL10Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-38489HIGH7.3Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-38488HIGH8.8Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-37979MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 v...
CVE-2023-37977MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now