2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31996 | HIGH | 8.8 | 1.5% | May 23, 2023 | Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special character... |
| CVE-2023-31995 | MEDIUM | 5.4 | 0.3% | May 23, 2023 | Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-31994 | MEDIUM | 5.3 | 0.6% | May 23, 2023 | Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the... |
| CVE-2023-31826 | HIGH | 7.8 | 0.3% | May 23, 2023 | Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attacker... |
| CVE-2023-31814 | CRITICAL | 9.8 | 0.9% | May 23, 2023 | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php. |
| CVE-2023-31741 | HIGH | 7.2 | 2.7% | May 23, 2023 | There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain... |
| CVE-2023-31740 | HIGH | 7.2 | 2.7% | May 23, 2023 | There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain... |
| CVE-2023-31708 | MEDIUM | 4.3 | 0.3% | May 23, 2023 | A Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a c... |
| CVE-2023-31670 | HIGH | 7.5 | 0.8% | May 23, 2023 | An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a ... |
| CVE-2023-31664 | MEDIUM | 6.1 | 1.2% | May 23, 2023 | A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.... |
| CVE-2023-29919 | CRITICAL | 9.1 | 60.2% | May 23, 2023 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t... |
| CVE-2023-27068 | CRITICAL | 9.8 | 1.7% | May 23, 2023 | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary ... |
| CVE-2023-25440 | MEDIUM | 5.4 | 2.5% | May 23, 2023 | Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe... |
| CVE-2023-2505 | HIGH | 8.8 | 0.3% | May 22, 2023 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files... |
| CVE-2023-2504 | CRITICAL | 9.8 | 0.5% | May 22, 2023 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-code... |
| CVE-2023-31816 | MEDIUM | 6.1 | 0.5% | May 22, 2023 | IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scri... |
| CVE-2023-25183 | HIGH | 7.2 | 0.6% | May 22, 2023 | In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a n... |
| CVE-2023-31689 | CRITICAL | 9.8 | 21.8% | May 22, 2023 | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.ph... |
| CVE-2023-31245 | MEDIUM | 6.1 | 0.4% | May 22, 2023 | Devices using Snap One OvrC cloud are sent to a web address when accessing a web management int... |
| CVE-2023-31241 | CRITICAL | 10 | 0.8% | May 22, 2023 | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright. |
| CVE-2023-31240 | CRITICAL | 9.8 | 0.5% | May 22, 2023 | Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network... |
| CVE-2023-31193 | HIGH | 7.5 | 0.4% | May 22, 2023 | Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.... |
| CVE-2023-29838 | HIGH | 7.8 | 0.2% | May 22, 2023 | Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate... |
| CVE-2023-28649 | HIGH | 7.5 | 0.5% | May 22, 2023 | The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A ... |
| CVE-2023-28412 | MEDIUM | 5.3 | 0.5% | May 22, 2023 | When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now