2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32436 | HIGH | 7.1 | 0.2% | Jan 10, 2024 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3. An app may be able to ca... |
| CVE-2023-32401 | HIGH | 7.8 | 0.2% | Jan 10, 2024 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big S... |
| CVE-2023-32383 | HIGH | 7.8 | 0.3% | Jan 10, 2024 | This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed i... |
| CVE-2023-32378 | HIGH | 7.8 | 0.2% | Jan 10, 2024 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS B... |
| CVE-2023-32366 | HIGH | 7.8 | 0.2% | Jan 10, 2024 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.5, ... |
| CVE-2023-51127 | HIGH | 7.5 | 1.3% | Jan 10, 2024 | FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access... |
| CVE-2023-29445 | HIGH | 7.8 | 0.2% | Jan 10, 2024 | An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent... |
| CVE-2023-50916 | HIGH | 7.2 | 4.6% | Jan 10, 2024 | Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted ch... |
| CVE-2023-46712 | HIGH | 8.8 | 0.7% | Jan 10, 2024 | A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 throug... |
| CVE-2023-44250 | HIGH | 8.8 | 0.9% | Jan 10, 2024 | An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 an... |
| CVE-2023-29444 | HIGH | 7.3 | 0.2% | Jan 10, 2024 | An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent... |
| CVE-2023-49738 | HIGH | 7.5 | 1.3% | Jan 10, 2024 | An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15f... |
| CVE-2023-49715 | HIGH | 8.8 | 1.4% | Jan 10, 2024 | A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo d... |
| CVE-2023-49589 | HIGH | 8.8 | 0.9% | Jan 10, 2024 | An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi... |
| CVE-2023-45139 | HIGH | 7.5 | 1.2% | Jan 10, 2024 | fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Inject... |
| CVE-2023-41056 | HIGH | 8.1 | 2.6% | Jan 10, 2024 | Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can res... |
| CVE-2023-48261 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48260 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48259 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft... |
| CVE-2023-48258 | HIGH | 8.1 | 0.2% | Jan 10, 2024 | The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP reque... |
| CVE-2023-48257 | HIGH | 8.8 | 0.5% | Jan 10, 2024 | The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code... |
| CVE-2023-48253 | HIGH | 8.8 | 0.9% | Jan 10, 2024 | The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication datab... |
| CVE-2023-48252 | HIGH | 8.8 | 0.6% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft... |
| CVE-2023-48247 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application... |
| CVE-2023-48243 | HIGH | 8.8 | 1.1% | Jan 10, 2024 | The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now