2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-32436HIGH7.1The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3. An app may be able to ca...
CVE-2023-32401HIGH7.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big S...
CVE-2023-32383HIGH7.8This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed i...
CVE-2023-32378HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS B...
CVE-2023-32366HIGH7.8An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.5, ...
CVE-2023-51127HIGH7.5FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access...
CVE-2023-29445HIGH7.8An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent...
CVE-2023-50916HIGH7.2Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted ch...
CVE-2023-46712HIGH8.8A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 throug...
CVE-2023-44250HIGH8.8An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 an...
CVE-2023-29444HIGH7.3An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent...
CVE-2023-49738HIGH7.5An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15f...
CVE-2023-49715HIGH8.8A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo d...
CVE-2023-49589HIGH8.8An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi...
CVE-2023-45139HIGH7.5fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Inject...
CVE-2023-41056HIGH8.1Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can res...
CVE-2023-48261HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48260HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48259HIGH7.5The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft...
CVE-2023-48258HIGH8.1The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP reque...
CVE-2023-48257HIGH8.8The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code...
CVE-2023-48253HIGH8.8The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication datab...
CVE-2023-48252HIGH8.8The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft...
CVE-2023-48247HIGH7.5The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application...
CVE-2023-48243HIGH8.8The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now