2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31996HIGH8.8Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special character...
CVE-2023-31995MEDIUM5.4Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-31994MEDIUM5.3Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the...
CVE-2023-31826HIGH7.8Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attacker...
CVE-2023-31814CRITICAL9.8D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
CVE-2023-31741HIGH7.2There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain...
CVE-2023-31740HIGH7.2There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain...
CVE-2023-31708MEDIUM4.3A Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a c...
CVE-2023-31670HIGH7.5An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a ...
CVE-2023-31664MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2....
CVE-2023-29919CRITICAL9.1SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t...
CVE-2023-27068CRITICAL9.8Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary ...
CVE-2023-25440MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe...
CVE-2023-2505HIGH8.8 The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files...
CVE-2023-2504CRITICAL9.8 Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-code...
CVE-2023-31816MEDIUM6.1IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scri...
CVE-2023-25183HIGH7.2 In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a n...
CVE-2023-31689CRITICAL9.8In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.ph...
CVE-2023-31245MEDIUM6.1 Devices using Snap One OvrC cloud are sent to a web address when accessing a web management int...
CVE-2023-31241CRITICAL10Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
CVE-2023-31240CRITICAL9.8Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network...
CVE-2023-31193HIGH7.5 Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers....
CVE-2023-29838HIGH7.8Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate...
CVE-2023-28649HIGH7.5The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A ...
CVE-2023-28412MEDIUM5.3 When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now