2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3032 | HIGH | 8.8 | 0.8% | Jun 2, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modu... |
| CVE-2023-3031 | MEDIUM | 4.9 | 0.8% | Jun 2, 2023 | Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowi... |
| CVE-2023-3056 | CRITICAL | 9.8 | 1.2% | Jun 2, 2023 | A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown ... |
| CVE-2023-33731 | MEDIUM | 6.1 | 0.8% | Jun 2, 2023 | Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management co... |
| CVE-2023-33717 | MEDIUM | 5.5 | 0.3% | Jun 2, 2023 | mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but... |
| CVE-2023-28469 | MEDIUM | 5.5 | 0.2% | Jun 2, 2023 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2023-30604 | CRITICAL | 9.8 | 0.9% | Jun 2, 2023 | It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technolo... |
| CVE-2023-30603 | CRITICAL | 9.8 | 0.8% | Jun 2, 2023 | Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt t... |
| CVE-2023-30602 | HIGH | 7.5 | 0.5% | Jun 2, 2023 | Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacke... |
| CVE-2023-28705 | MEDIUM | 6.1 | 0.4% | Jun 2, 2023 | Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A re... |
| CVE-2023-28704 | HIGH | 8.8 | 1.0% | Jun 2, 2023 | Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated ... |
| CVE-2023-28703 | HIGH | 7.2 | 0.9% | Jun 2, 2023 | ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for... |
| CVE-2023-28702 | HIGH | 8.8 | 1.2% | Jun 2, 2023 | ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user... |
| CVE-2023-28701 | CRITICAL | 9.8 | 0.9% | Jun 2, 2023 | ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL c... |
| CVE-2023-28700 | MEDIUM | 6.8 | 0.3% | Jun 2, 2023 | OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area ... |
| CVE-2023-28699 | HIGH | 8.8 | 0.9% | Jun 2, 2023 | Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An a... |
| CVE-2023-28698 | CRITICAL | 9.8 | 0.8% | Jun 2, 2023 | Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can e... |
| CVE-2023-25780 | MEDIUM | 5.7 | 0.3% | Jun 2, 2023 | It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A ... |
| CVE-2023-3000 | CRITICAL | 9.8 | 0.8% | Jun 2, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technolog... |
| CVE-2023-2835 | MEDIUM | 6.1 | 0.7% | Jun 2, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in ... |
| CVE-2023-1159 | MEDIUM | 4.8 | 0.4% | Jun 2, 2023 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and i... |
| CVE-2023-2063 | HIGH | 7.3 | 0.6% | Jun 2, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC ... |
| CVE-2023-2062 | MEDIUM | 6.2 | 0.3% | Jun 2, 2023 | Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-E... |
| CVE-2023-2061 | HIGH | 7.5 | 0.5% | Jun 2, 2023 | Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/... |
| CVE-2023-2060 | HIGH | 7.5 | 0.8% | Jun 2, 2023 | Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now