2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34104HIGH7.5fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names...
CVE-2023-33747HIGH7.8CloudPanel v2.2.2 allows attackers to execute a path traversal.
CVE-2023-33613MEDIUM5.5axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. T...
CVE-2023-27126MEDIUM4.6The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused acros...
CVE-2023-34111CRITICAL9.8The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerabili...
CVE-2023-32203HIGH7.8Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This coul...
CVE-2023-31606HIGH7.5A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0...
CVE-2023-31278HIGH7.8Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This coul...
CVE-2023-31244HIGH7.8 The affected product does not properly validate user-supplied data. If a user opens a maliciously for...
CVE-2023-2132HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions star...
CVE-2023-29503HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). Th...
CVE-2023-28653HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing project files (e.g....
CVE-2023-27916HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT...
CVE-2023-0921MEDIUM4.3A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16...
CVE-2023-32551MEDIUM6.1Landscape allowed URLs which caused open redirection.
CVE-2023-32550HIGH8.2Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain ...
CVE-2023-32549HIGH7.5Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
CVE-2023-32539HIGH7.8Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This coul...
CVE-2023-32289HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP...
CVE-2023-32281HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). ...
CVE-2023-32545HIGH7.8 The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CS...
CVE-2023-30948MEDIUM6.5A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gat...
CVE-2023-3123Rejected reason: Duplicate Assignment.
CVE-2023-33533HIGH8.8Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26...
CVE-2023-33532CRITICAL9.8There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker ga...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now