2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37145 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname param... |
| CVE-2023-37144 | CRITICAL | 9.8 | 2.1% | Jul 7, 2023 | Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the functio... |
| CVE-2023-3536 | MEDIUM | 6.1 | 0.3% | Jul 7, 2023 | A vulnerability was found in SimplePHPscripts Funeral Script PHP 3.1. It has been rated as problematic. Affected by this... |
| CVE-2023-3535 | MEDIUM | 6.1 | 0.3% | Jul 7, 2023 | A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this ... |
| CVE-2023-37308 | MEDIUM | 5.4 | 1.6% | Jul 7, 2023 | Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. |
| CVE-2023-34197 | MEDIUM | 5.4 | 3.0% | Jul 7, 2023 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 ... |
| CVE-2023-3534 | HIGH | 7.5 | 0.5% | Jul 7, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk... |
| CVE-2023-33008 | MEDIUM | 5.3 | 1.1% | Jul 7, 2023 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can... |
| CVE-2023-32183 | HIGH | 7.8 | 0.2% | Jul 7, 2023 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hac... |
| CVE-2023-3532 | MEDIUM | 5.4 | 0.4% | Jul 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1. |
| CVE-2023-35890 | MEDIUM | 5.5 | 0.1% | Jul 7, 2023 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encodin... |
| CVE-2023-37192 | HIGH | 7.5 | 0.5% | Jul 7, 2023 | Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within... |
| CVE-2023-35765 | MEDIUM | 6.5 | 0.4% | Jul 7, 2023 | PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentia... |
| CVE-2023-35120 | HIGH | 8.8 | 0.2% | Jul 7, 2023 | PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send... |
| CVE-2023-34995 | CRITICAL | 9.8 | 0.5% | Jul 7, 2023 | There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a su... |
| CVE-2023-34433 | CRITICAL | 9.8 | 0.3% | Jul 7, 2023 | PiiGAB M-Bus stores passwords using a weak hash algorithm. |
| CVE-2023-32652 | MEDIUM | 6.1 | 0.4% | Jul 7, 2023 | PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cros... |
| CVE-2023-36859 | CRITICAL | 9.8 | 0.6% | Jul 6, 2023 | PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbit... |
| CVE-2023-36829 | MEDIUM | 5.4 | 0.5% | Jul 6, 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2,... |
| CVE-2023-35987 | CRITICAL | 9.8 | 0.6% | Jul 6, 2023 | PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. |
| CVE-2023-33868 | CRITICAL | 9.8 | 0.5% | Jul 6, 2023 | The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic auth... |
| CVE-2023-31277 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | PiiGAB M-Bus transmits credentials in plaintext format. |
| CVE-2023-20899 | HIGH | 7.5 | 0.5% | Jul 6, 2023 | VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno... |
| CVE-2023-29824 | CRITICAL | 9.8 | 1.1% | Jul 6, 2023 | A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor an... |
| CVE-2023-3531 | MEDIUM | 5.4 | 0.5% | Jul 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now