2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51638CRITICAL9.8Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass...
CVE-2023-51635HIGH8.8NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows networ...
CVE-2023-51634HIGH7.5NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adj...
CVE-2023-39470HIGH7.2PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability al...
CVE-2023-24467CRITICAL9.8Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
CVE-2023-24466CRITICAL9.8Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200...
CVE-2023-27609MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NetTantra W...
CVE-2023-21270HIGH7.8In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions t...
CVE-2023-52921HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix possible UAF in amdgpu_cs_pass1() ...
CVE-2023-49952HIGH7.5Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
CVE-2023-39180HIGH7.5A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releas...
CVE-2023-39179HIGH7.5A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack o...
CVE-2023-39176HIGH7.5A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue ...
CVE-2023-43091CRITICAL9.8A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. ...
CVE-2023-6110MEDIUM5.5A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other ex...
CVE-2023-4639HIGH7.4A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requ...
CVE-2023-1419MEDIUM5.9A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some ...
CVE-2023-0657LOW3.4A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures local...
CVE-2023-20094MEDIUM4.3A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive ...
CVE-2023-20093MEDIUM4.4Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove...
CVE-2023-20092MEDIUM4.4Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove...
CVE-2023-20091MEDIUM5.1A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite...
CVE-2023-20090MEDIUM6.7A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges t...
CVE-2023-20060MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthentic...
CVE-2023-20039MEDIUM5.5A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerabilit...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now