2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25185HIGH7.8An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault ...
CVE-2023-34832CRITICAL9.8TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
CVE-2023-34660MEDIUM6.5jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
CVE-2023-34659CRITICAL9.8jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interfac...
CVE-2023-34645HIGH7.5jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
CVE-2023-34733MEDIUM6.8A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers...
CVE-2023-30625HIGH8.8rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1....
CVE-2023-30223HIGH7.5A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to sen...
CVE-2023-30222HIGH7.5An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to...
CVE-2023-2918Rejected reason: Duplicate Assignment.
CVE-2023-24243HIGH7.5CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2023-34795HIGH7.8xlsxio v0.1.2 to v0.2.34 was discovered to contain a free of uninitialized pointer in the xlsxioread_sheetlist_close() f...
CVE-2023-30453MEDIUM5.4The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter.
CVE-2023-25366CRITICAL9.8In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
CVE-2023-35783MEDIUM6.1The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TY...
CVE-2023-35782CRITICAL9.8The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.
CVE-2023-34548CRITICAL9.8Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
CVE-2023-20885MEDIUM6.5Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This...
CVE-2023-3294MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e1...
CVE-2023-26537MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions.
CVE-2023-26527MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
CVE-2023-25974MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
CVE-2023-3293MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
CVE-2023-27420MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions.
CVE-2023-26515MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now