2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3032HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modu...
CVE-2023-3031MEDIUM4.9Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowi...
CVE-2023-3056CRITICAL9.8A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown ...
CVE-2023-33731MEDIUM6.1Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management co...
CVE-2023-33717MEDIUM5.5mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but...
CVE-2023-28469MEDIUM5.5An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2023-30604CRITICAL9.8It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technolo...
CVE-2023-30603CRITICAL9.8Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt t...
CVE-2023-30602HIGH7.5Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacke...
CVE-2023-28705MEDIUM6.1Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A re...
CVE-2023-28704HIGH8.8Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated ...
CVE-2023-28703HIGH7.2ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for...
CVE-2023-28702HIGH8.8ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user...
CVE-2023-28701CRITICAL9.8ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL c...
CVE-2023-28700MEDIUM6.8OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area ...
CVE-2023-28699HIGH8.8Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An a...
CVE-2023-28698CRITICAL9.8Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can e...
CVE-2023-25780MEDIUM5.7It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A ...
CVE-2023-3000CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technolog...
CVE-2023-2835MEDIUM6.1The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in ...
CVE-2023-1159MEDIUM4.8The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and i...
CVE-2023-2063HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC ...
CVE-2023-2062MEDIUM6.2Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-E...
CVE-2023-2061HIGH7.5Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/...
CVE-2023-2060HIGH7.5Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now