2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37802Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-37801Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-37800Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36169Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36168Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36166Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36165Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-30791MEDIUM4.6Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML e...
CVE-2023-2507MEDIUM6.1CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is op...
CVE-2023-2268HIGH7.5Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.
CVE-2023-3682CRITICAL9.8A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an...
CVE-2023-3681MEDIUM6.1A vulnerability classified as problematic was found in Campcodes Retro Cellphone Online Store 1.0. This vulnerability af...
CVE-2023-3680CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affe...
CVE-2023-3679CRITICAL9.8A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as critical. Affect...
CVE-2023-3678CRITICAL9.8A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affecte...
CVE-2023-38350MEDIUM5.4PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
CVE-2023-38349HIGH8.8PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
CVE-2023-35802CRITICAL9.8IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol...
CVE-2023-37794CRITICAL9.8WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.a...
CVE-2023-37793CRITICAL9.8WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.
CVE-2023-38337HIGH7.5rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag...
CVE-2023-38336CRITICAL9.8netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related i...
CVE-2023-37268HIGH8.8Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a u...
CVE-2023-36818HIGH7.5Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar secti...
CVE-2023-36466MEDIUM4.3Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to b...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now