2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28959MEDIUM6.5An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS ...
CVE-2023-24504MEDIUM6.5Electra Central AC unit – Adjacent attacker may cause the unit to connect to unauthorized update server.
CVE-2023-24503MEDIUM6.5Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
CVE-2023-24502MEDIUM6.5Electra Central AC unit – The unit opens an AP with an easily calculated password.
CVE-2023-24501CRITICAL9.8Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
CVE-2023-24500MEDIUM6.5Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
CVE-2023-1697MEDIUM6.5An Improper Handling of Missing Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS ...
CVE-2023-30548MEDIUM4.3gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing lib...
CVE-2023-27911HIGH7.8A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodes...
CVE-2023-27910HIGH7.8A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autode...
CVE-2023-27909HIGH7.8An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through mali...
CVE-2023-27907HIGH7.8A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerabili...
CVE-2023-27906HIGH7.8A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerabilit...
CVE-2023-25010HIGH7.8A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which ma...
CVE-2023-30769CRITICAL9.8Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, se...
CVE-2023-2130CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Purchase Order Management System 1.0. Affected i...
CVE-2023-29004MEDIUM6.5hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerabi...
CVE-2023-27525MEDIUM4.3An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods ...
CVE-2023-25504MEDIUM6.5A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import data...
CVE-2023-29665CRITICAL9.8D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
CVE-2023-27705HIGH7.5APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.
CVE-2023-1831HIGH7.5Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op...
CVE-2023-27755HIGH8.8go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.
CVE-2023-1873CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircar...
CVE-2023-27844CRITICAL9.8SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now