2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37477HIGH8.81Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability ...
CVE-2023-36670CRITICAL9.8A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute ...
CVE-2023-30383HIGH7.5TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer...
CVE-2023-30153CRITICAL9.8An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3...
CVE-2023-28021HIGH7.5The BigFix WebUI uses weak cipher suites.
CVE-2023-28020MEDIUM6.1 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external s...
CVE-2023-38257HIGH7.5Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that cou...
CVE-2023-36669CRITICAL9.8Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attacke...
CVE-2023-35763MEDIUM5.5Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthen...
CVE-2023-35189CRITICAL9.8Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an...
CVE-2023-34330HIGH8.8AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish E...
CVE-2023-34329HIGH8AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP h...
CVE-2023-33871HIGH7.5Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a directory traversal vulnerability that could allow an un...
CVE-2023-33329MEDIUM4.8Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 v...
CVE-2023-33312MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <= 1.0 versions.
CVE-2023-28019HIGH8.8Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL querie...
CVE-2023-37259MEDIUM5.4matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature i...
CVE-2023-33231MEDIUM6.1XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-0160MEDIUM5.5A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the sy...
CVE-2023-34035MEDIUM5.3Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authoriz...
CVE-2023-33265HIGH8.8In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions p...
CVE-2023-2263HIGH7.5 The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connectio...
CVE-2023-36384MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 ...
CVE-2023-36383MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plu...
CVE-2023-36120Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now