2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41611MEDIUM6.5Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
CVE-2023-41610HIGH8.8Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
CVE-2023-47105HIGH8.6exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd p...
CVE-2023-49203HIGH7.5Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb man...
CVE-2023-28457HIGH7.5An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and i...
CVE-2023-28456HIGH7.5An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more...
CVE-2023-28455HIGH7.5An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using...
CVE-2023-28452HIGH7.5An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a ...
CVE-2023-28451HIGH7.5An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which ...
CVE-2023-45854HIGH7.5A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shoppin...
CVE-2023-43753MEDIUM6.8Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enabl...
CVE-2023-43626HIGH8.7Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable ...
CVE-2023-42772HIGH8.7Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to pot...
CVE-2023-41833HIGH8.7A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalat...
CVE-2023-25546LOW2.5Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denia...
CVE-2023-23904MEDIUM6.9NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially en...
CVE-2023-22351MEDIUM6.9Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable esca...
CVE-2023-3410MEDIUM5.4The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up...
CVE-2023-6841HIGH7.5A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an atta...
CVE-2023-37234CRITICAL9.8Loftware Spectrum through 4.6 has unprotected JMX Registry.
CVE-2023-37233HIGH8.8Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
CVE-2023-37232HIGH7.5Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
CVE-2023-36103CRITICAL9.8Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run...
CVE-2023-44254MEDIUM6.5An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7....
CVE-2023-37231CRITICAL9.8Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now