2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31148HIGH8.8An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller ...
CVE-2023-30194CRITICAL9.8Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
CVE-2023-2310MEDIUM5.3A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL Real-Time Automation C...
CVE-2023-32076MEDIUM5.5in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and...
CVE-2023-32070MEDIUM6.1XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attribu...
CVE-2023-0008MEDIUM4.4A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator ...
CVE-2023-0007MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authe...
CVE-2023-31568HIGH8.8Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
CVE-2023-31567HIGH8.8Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAES...
CVE-2023-31566HIGH8.8Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted...
CVE-2023-31557Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-2664. Reason: This record is a reservatio...
CVE-2023-31556MEDIUM6.5podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyPare...
CVE-2023-31555MEDIUM6.5podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.
CVE-2023-31554Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-2663. Reason: This record is a reservatio...
CVE-2023-30356HIGH7.5Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers t...
CVE-2023-30354CRITICAL9.8Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UA...
CVE-2023-30353CRITICAL9.8Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML docu...
CVE-2023-30352CRITICAL9.8Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for ...
CVE-2023-30351HIGH7.5Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for ...
CVE-2023-2630MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-2629HIGH7.8Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to ...
CVE-2023-31910HIGH7.8Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_functio...
CVE-2023-31908HIGH7.8Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component ecma_builtin_typedar...
CVE-2023-31907HIGH7.8Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerr...
CVE-2023-31906HIGH7.8Jerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_ident...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now