2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31490HIGH7.5An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub...
CVE-2023-31489MEDIUM5.5An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_ll...
CVE-2023-31476HIGH7.5An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an e...
CVE-2023-31144MEDIUM6.1Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed t...
CVE-2023-30088MEDIUM5.5An issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function i...
CVE-2023-30087MEDIUM5.5Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the m...
CVE-2023-30086MEDIUM5.5Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiff...
CVE-2023-30085MEDIUM5.5Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via...
CVE-2023-30084MEDIUM5.5An issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal functio...
CVE-2023-30083MEDIUM5.5Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via...
CVE-2023-25834MEDIUM5.4Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This i...
CVE-2023-32060MEDIUM6.5DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3...
CVE-2023-31143CRITICAL9.8mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in versi...
CVE-2023-31139HIGH7.5DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3...
CVE-2023-31138MEDIUM6.5DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3...
CVE-2023-31982HIGH7.8Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture....
CVE-2023-31981HIGH7.8Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
CVE-2023-31979HIGH7.8Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
CVE-2023-31976HIGH8.8libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_ut...
CVE-2023-31973MEDIUM5.5yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Mul...
CVE-2023-31137HIGH7.5MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely ...
CVE-2023-31136MEDIUM5.9PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with...
CVE-2023-31134MEDIUM5.4Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated fr...
CVE-2023-29462HIGH8.8An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that...
CVE-2023-29461CRITICAL9.8An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now