2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37145CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname param...
CVE-2023-37144CRITICAL9.8Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the functio...
CVE-2023-3536MEDIUM6.1A vulnerability was found in SimplePHPscripts Funeral Script PHP 3.1. It has been rated as problematic. Affected by this...
CVE-2023-3535MEDIUM6.1A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this ...
CVE-2023-37308MEDIUM5.4Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
CVE-2023-34197MEDIUM5.4Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 ...
CVE-2023-3534HIGH7.5A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk...
CVE-2023-33008MEDIUM5.3Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can...
CVE-2023-32183HIGH7.8Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hac...
CVE-2023-3532MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
CVE-2023-35890MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encodin...
CVE-2023-37192HIGH7.5Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within...
CVE-2023-35765MEDIUM6.5 PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentia...
CVE-2023-35120HIGH8.8 PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send...
CVE-2023-34995CRITICAL9.8 There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a su...
CVE-2023-34433CRITICAL9.8 PiiGAB M-Bus stores passwords using a weak hash algorithm.
CVE-2023-32652MEDIUM6.1 PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cros...
CVE-2023-36859CRITICAL9.8 PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbit...
CVE-2023-36829MEDIUM5.4Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2,...
CVE-2023-35987CRITICAL9.8 PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
CVE-2023-33868CRITICAL9.8 The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic auth...
CVE-2023-31277HIGH7.5 PiiGAB M-Bus transmits credentials in plaintext format.
CVE-2023-20899HIGH7.5VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno...
CVE-2023-29824CRITICAL9.8A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor an...
CVE-2023-3531MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now