2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0545MEDIUM4.8The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-0152MEDIUM5.4The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes be...
CVE-2023-27989MEDIUM6.5A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could...
CVE-2023-3066HIGH8.1Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonat...
CVE-2023-3065CRITICAL9.1Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue af...
CVE-2023-3064MEDIUM5.3Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2...
CVE-2023-3100CRITICAL9.8A vulnerability, which was classified as critical, has been found in IBOS 4.5.5. Affected by this issue is the function ...
CVE-2023-3099HIGH7.1A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerabilit...
CVE-2023-3098HIGH7.8A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function...
CVE-2023-3097HIGH7.8A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been rated as critical. This issue a...
CVE-2023-3096HIGH7.8A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been declared as critical. This vuln...
CVE-2023-34411HIGH7.5The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!D...
CVE-2023-32217HIGH8.8IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, Identity...
CVE-2023-0636CRITICAL9.8Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2C...
CVE-2023-0635CRITICAL9.8Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021...
CVE-2023-34410MEDIUM5.3An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate valida...
CVE-2023-34408MEDIUM5.4DokuWiki before 2023-04-04a allows XSS via RSS titles.
CVE-2023-34407HIGH7.5OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a UR...
CVE-2023-32334MEDIUM5.3IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL ...
CVE-2023-27861MEDIUM5.9IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could ...
CVE-2023-0041HIGH8.8IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration...
CVE-2023-27285HIGH7.8IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checki...
CVE-2023-22862HIGH7.5IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method...
CVE-2023-3095MEDIUM6.5Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-3094CRITICAL9.8A vulnerability classified as critical has been found in code-projects Agro-School Management System 1.0. Affected is th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now