2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23343 | MEDIUM | 6.1 | 0.3% | Jun 22, 2023 | A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use tran... |
| CVE-2023-3128 | CRITICAL | 9.8 | 4.1% | Jun 22, 2023 | Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a... |
| CVE-2023-35133 | HIGH | 7.5 | 0.8% | Jun 22, 2023 | An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw aff... |
| CVE-2023-35132 | MEDIUM | 6.3 | 0.8% | Jun 22, 2023 | A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, ... |
| CVE-2023-35131 | MEDIUM | 6.1 | 0.7% | Jun 22, 2023 | Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2,... |
| CVE-2023-34553 | MEDIUM | 6.5 | 0.3% | Jun 22, 2023 | An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack. |
| CVE-2023-32320 | HIGH | 7.5 | 0.9% | Jun 22, 2023 | Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are... |
| CVE-2023-30347 | MEDIUM | 4.8 | 0.5% | Jun 22, 2023 | Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA ... |
| CVE-2023-28094 | CRITICAL | 9.8 | 0.5% | Jun 22, 2023 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be util... |
| CVE-2023-36359 | HIGH | 7.5 | 0.8% | Jun 22, 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflo... |
| CVE-2023-36358 | HIGH | 7.7 | 0.7% | Jun 22, 2023 | TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflo... |
| CVE-2023-36357 | HIGH | 7.7 | 0.8% | Jun 22, 2023 | An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND... |
| CVE-2023-36356 | HIGH | 7.7 | 0.7% | Jun 22, 2023 | TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read ou... |
| CVE-2023-36355 | CRITICAL | 9.9 | 31.7% | Jun 22, 2023 | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg... |
| CVE-2023-36354 | HIGH | 7.5 | 0.8% | Jun 22, 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contai... |
| CVE-2023-32571 | CRITICAL | 9.8 | 34.9% | Jun 22, 2023 | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted... |
| CVE-2023-2991 | MEDIUM | 5.3 | 0.6% | Jun 22, 2023 | Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial num... |
| CVE-2023-2990 | HIGH | 7.5 | 0.9% | Jun 22, 2023 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed messag... |
| CVE-2023-2989 | CRITICAL | 9.1 | 1.0% | Jun 22, 2023 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server,... |
| CVE-2023-28800 | MEDIUM | 6.1 | 0.5% | Jun 22, 2023 | When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS ... |
| CVE-2023-28799 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this param... |
| CVE-2023-27083 | HIGH | 7.2 | 1.2% | Jun 22, 2023 | An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code ... |
| CVE-2023-36243 | HIGH | 7.8 | 0.3% | Jun 22, 2023 | FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c. |
| CVE-2023-36239 | HIGH | 8.8 | 0.7% | Jun 22, 2023 | libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c. |
| CVE-2023-34923 | HIGH | 8.1 | 0.7% | Jun 22, 2023 | XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credential... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now