2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32347CRITICAL9.8 Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify d...
CVE-2023-32346MEDIUM5.3 Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devic...
CVE-2023-31923HIGH8.8Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an auth...
CVE-2023-25448HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 ver...
CVE-2023-25447HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions.
CVE-2023-31454HIGH7.5Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss...
CVE-2023-31453HIGH7.5Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss...
CVE-2023-31206HIGH7.5Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache...
CVE-2023-31779MEDIUM5.4Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can...
CVE-2023-31058HIGH7.5Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In...
CVE-2023-2597CRITICAL9.1In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ...
CVE-2023-2832HIGH7.2 SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.
CVE-2023-28709HIGH7.5The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 a...
CVE-2023-25537HIGH7.8 Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Ou...
CVE-2023-23797HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions.
CVE-2023-23813HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
CVE-2023-23712HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions.
CVE-2023-23680HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Bob Goetz WP-TopBar plugin <= 5.36 versions.
CVE-2023-22714HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions.
CVE-2023-22709HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Atif N SRS Simple Hits Counter plugin <= 1.1.0 versions.
CVE-2023-22692HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.
CVE-2023-22688HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Abdul Ibad WP Tabs Slides plugin <= 2.0.3 versions.
CVE-2023-33236CRITICAL9.8MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that ca...
CVE-2023-33235HIGH8.8MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH...
CVE-2023-33297HIGH7.5Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumpt...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now