2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23343MEDIUM6.1A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use tran...
CVE-2023-3128CRITICAL9.8Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a...
CVE-2023-35133HIGH7.5An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw aff...
CVE-2023-35132MEDIUM6.3A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, ...
CVE-2023-35131MEDIUM6.1Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2,...
CVE-2023-34553MEDIUM6.5An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.
CVE-2023-32320HIGH7.5Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are...
CVE-2023-30347MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA ...
CVE-2023-28094CRITICAL9.8Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be util...
CVE-2023-36359HIGH7.5TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflo...
CVE-2023-36358HIGH7.7TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflo...
CVE-2023-36357HIGH7.7An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND...
CVE-2023-36356HIGH7.7TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read ou...
CVE-2023-36355CRITICAL9.9TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg...
CVE-2023-36354HIGH7.5TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contai...
CVE-2023-32571CRITICAL9.8Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted...
CVE-2023-2991MEDIUM5.3Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial num...
CVE-2023-2990HIGH7.5Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed messag...
CVE-2023-2989CRITICAL9.1Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server,...
CVE-2023-28800MEDIUM6.1When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS ...
CVE-2023-28799MEDIUM6.1A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this param...
CVE-2023-27083HIGH7.2An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code ...
CVE-2023-36243HIGH7.8FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c.
CVE-2023-36239HIGH8.8libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.
CVE-2023-34923HIGH8.1XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credential...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now