2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28959 | MEDIUM | 6.5 | 0.3% | Apr 17, 2023 | An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS ... |
| CVE-2023-24504 | MEDIUM | 6.5 | 0.3% | Apr 17, 2023 | Electra Central AC unit – Adjacent attacker may cause the unit to connect to unauthorized update server. |
| CVE-2023-24503 | MEDIUM | 6.5 | 0.2% | Apr 17, 2023 | Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
| CVE-2023-24502 | MEDIUM | 6.5 | 0.2% | Apr 17, 2023 | Electra Central AC unit – The unit opens an AP with an easily calculated password. |
| CVE-2023-24501 | CRITICAL | 9.8 | 0.6% | Apr 17, 2023 | Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. |
| CVE-2023-24500 | MEDIUM | 6.5 | 0.2% | Apr 17, 2023 | Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
| CVE-2023-1697 | MEDIUM | 6.5 | 0.3% | Apr 17, 2023 | An Improper Handling of Missing Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS ... |
| CVE-2023-30548 | MEDIUM | 4.3 | 0.9% | Apr 17, 2023 | gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing lib... |
| CVE-2023-27911 | HIGH | 7.8 | 0.6% | Apr 17, 2023 | A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodes... |
| CVE-2023-27910 | HIGH | 7.8 | 0.5% | Apr 17, 2023 | A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autode... |
| CVE-2023-27909 | HIGH | 7.8 | 0.5% | Apr 17, 2023 | An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through mali... |
| CVE-2023-27907 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerabili... |
| CVE-2023-27906 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerabilit... |
| CVE-2023-25010 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which ma... |
| CVE-2023-30769 | CRITICAL | 9.8 | 0.9% | Apr 17, 2023 | Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, se... |
| CVE-2023-2130 | CRITICAL | 9.8 | 4.1% | Apr 17, 2023 | A vulnerability classified as critical has been found in SourceCodester Purchase Order Management System 1.0. Affected i... |
| CVE-2023-29004 | MEDIUM | 6.5 | 0.9% | Apr 17, 2023 | hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerabi... |
| CVE-2023-27525 | MEDIUM | 4.3 | 0.8% | Apr 17, 2023 | An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods ... |
| CVE-2023-25504 | MEDIUM | 6.5 | 0.9% | Apr 17, 2023 | A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import data... |
| CVE-2023-29665 | CRITICAL | 9.8 | 1.2% | Apr 17, 2023 | D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings. |
| CVE-2023-27705 | HIGH | 7.5 | 0.8% | Apr 17, 2023 | APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. |
| CVE-2023-1831 | HIGH | 7.5 | 0.4% | Apr 17, 2023 | Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op... |
| CVE-2023-27755 | HIGH | 8.8 | 0.8% | Apr 17, 2023 | go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. |
| CVE-2023-1873 | CRITICAL | 9.8 | 0.7% | Apr 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircar... |
| CVE-2023-27844 | CRITICAL | 9.8 | 0.8% | Apr 17, 2023 | SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now