2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3660MEDIUM6.1A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this ...
CVE-2023-2003CRITICAL9.8Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a...
CVE-2023-26597HIGH7.5Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Hon...
CVE-2023-25948HIGH7.5Server information leak of configuration data when an error is generated in response to a specially crafted message. See...
CVE-2023-3659MEDIUM6.1A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affect...
CVE-2023-3658CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affect...
CVE-2023-25770HIGH7.5Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. S...
CVE-2023-25178CRITICAL9.8Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notifi...
CVE-2023-25078HIGH7.5Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a sp...
CVE-2023-24480HIGH7.5Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for ...
CVE-2023-24474HIGH7.5Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
CVE-2023-23585HIGH7.5Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific con...
CVE-2023-22435HIGH7.5Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
CVE-2023-3657CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. T...
CVE-2023-29458HIGH7.5Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too...
CVE-2023-29457MEDIUM6.1Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The scr...
CVE-2023-29456MEDIUM5.4URL validation scheme receives input from a user and then parses it to identify its various components. The validation s...
CVE-2023-29455MEDIUM6.1Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web applic...
CVE-2023-29454MEDIUM5.4Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web a...
CVE-2023-29452MEDIUM5.4 Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attrib...
CVE-2023-29451HIGH7.5Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server o...
CVE-2023-29450HIGH7.5JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of u...
CVE-2023-29449MEDIUM4.9JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Prep...
CVE-2023-3319MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay ...
CVE-2023-37415HIGH8.8Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now