2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31148 | HIGH | 8.8 | 1.1% | May 10, 2023 | An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller ... |
| CVE-2023-30194 | CRITICAL | 9.8 | 32.4% | May 10, 2023 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). |
| CVE-2023-2310 | MEDIUM | 5.3 | 0.5% | May 10, 2023 | A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL Real-Time Automation C... |
| CVE-2023-32076 | MEDIUM | 5.5 | 0.2% | May 10, 2023 | in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and... |
| CVE-2023-32070 | MEDIUM | 6.1 | 0.7% | May 10, 2023 | XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attribu... |
| CVE-2023-0008 | MEDIUM | 4.4 | 0.5% | May 10, 2023 | A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator ... |
| CVE-2023-0007 | MEDIUM | 4.8 | 0.4% | May 10, 2023 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authe... |
| CVE-2023-31568 | HIGH | 8.8 | 0.7% | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. |
| CVE-2023-31567 | HIGH | 8.8 | 0.7% | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAES... |
| CVE-2023-31566 | HIGH | 8.8 | 0.7% | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted... |
| CVE-2023-31557 | — | — | — | May 10, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-2664. Reason: This record is a reservatio... |
| CVE-2023-31556 | MEDIUM | 6.5 | 0.7% | May 10, 2023 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyPare... |
| CVE-2023-31555 | MEDIUM | 6.5 | 0.6% | May 10, 2023 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad. |
| CVE-2023-31554 | — | — | — | May 10, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-2663. Reason: This record is a reservatio... |
| CVE-2023-30356 | HIGH | 7.5 | 0.3% | May 10, 2023 | Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers t... |
| CVE-2023-30354 | CRITICAL | 9.8 | 0.4% | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UA... |
| CVE-2023-30353 | CRITICAL | 9.8 | 1.2% | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML docu... |
| CVE-2023-30352 | CRITICAL | 9.8 | 0.7% | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for ... |
| CVE-2023-30351 | HIGH | 7.5 | 0.2% | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for ... |
| CVE-2023-2630 | MEDIUM | 4.8 | 0.6% | May 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-2629 | HIGH | 7.8 | 0.4% | May 10, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to ... |
| CVE-2023-31910 | HIGH | 7.8 | 0.3% | May 10, 2023 | Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_functio... |
| CVE-2023-31908 | HIGH | 7.8 | 0.3% | May 10, 2023 | Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component ecma_builtin_typedar... |
| CVE-2023-31907 | HIGH | 7.8 | 0.3% | May 10, 2023 | Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerr... |
| CVE-2023-31906 | HIGH | 7.8 | 0.3% | May 10, 2023 | Jerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_ident... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now