2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28522HIGH8.8IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-For...
CVE-2023-28520MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ...
CVE-2023-30330CRITICAL9.8SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42...
CVE-2023-2666HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
CVE-2023-2665HIGH7.5Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to...
CVE-2023-29809CRITICAL9.8SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit...
CVE-2023-29808MEDIUM6.1Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.
CVE-2023-29790HIGH7.5kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
CVE-2023-30192CRITICAL9.8Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
CVE-2023-32059HIGH7.5Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, internal calls wit...
CVE-2023-31531HIGH8.8Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number pa...
CVE-2023-31530HIGH8.8Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices...
CVE-2023-31529HIGH8.8Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone para...
CVE-2023-31528HIGH8.8Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list paramete...
CVE-2023-31508Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2020-15178. Reason: This record is a duplicate of CVE-2020-...
CVE-2023-31502HIGH7.2Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the co...
CVE-2023-29286MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability ...
CVE-2023-29285HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could r...
CVE-2023-29284HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that ...
CVE-2023-29283HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2023-29282HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could r...
CVE-2023-29281HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-29280HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-29279MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le...
CVE-2023-29278HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now