2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36458HIGH8.81Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticat...
CVE-2023-36457HIGH8.81Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticat...
CVE-2023-35940HIGH7.5GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor...
CVE-2023-35939HIGH8.1GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor...
CVE-2023-35936MEDIUM5Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this lib...
CVE-2023-30207MEDIUM5.5A divide by zero issue discovered in Kodi Home Theater Software 19.5 and earlier allows attackers to cause a denial of s...
CVE-2023-36624HIGH7.8Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via th...
CVE-2023-36623HIGH7.8The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC addre...
CVE-2023-36622HIGH7.2The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated admin...
CVE-2023-35924CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI in...
CVE-2023-34654MEDIUM6.1taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34457HIGH7.5MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to vers...
CVE-2023-34244MEDIUM6.1GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malici...
CVE-2023-34107MEDIUM6.5GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0....
CVE-2023-27199MEDIUM6.7PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and us...
CVE-2023-27198MEDIUM6.8PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the e...
CVE-2023-27197MEDIUM6.7PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a craft...
CVE-2023-35001HIGH7.8Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP...
CVE-2023-34473HIGH8.8 AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful ...
CVE-2023-34472MEDIUM6.5AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in ...
CVE-2023-34471HIGH8.1 AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-b...
CVE-2023-34338CRITICAL9.8AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-...
CVE-2023-34337HIGH8.8 AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based mess...
CVE-2023-31248HIGH7.8Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check...
CVE-2023-35863MEDIUM5.3In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now