2023 CVE Vulnerabilities

31,441 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29581MEDIUM5.5yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE:...
CVE-2023-28488MEDIUM6.5client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) ...
CVE-2023-27703LOW3.3The Android version of pikpak v1.29.2 was discovered to contain an information leak via the debug interface.
CVE-2023-1872HIGH7A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalatio...
CVE-2023-29571MEDIUM5.5Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can ...
CVE-2023-27830CRITICAL9TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate fi...
CVE-2023-27775MEDIUM5.4A stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a craf...
CVE-2023-27704MEDIUM5.5Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS).
CVE-2023-27032CRITICAL9.8Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2023-23591MEDIUM4.9The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from appl...
CVE-2023-1874HIGH8.8The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. T...
CVE-2023-29580MEDIUM5.5yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/e...
CVE-2023-29574MEDIUM5.5Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
CVE-2023-27826HIGH8.8SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Inj...
CVE-2023-22616HIGH7.8An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before u...
CVE-2023-1829HIGH7.8A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve lo...
CVE-2023-30512MEDIUM6.5CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-clu...
CVE-2023-22613HIGH8.8An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attac...
CVE-2023-29576MEDIUM5.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function i...
CVE-2023-28808CRITICAL9.8Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the ...
CVE-2023-28314MEDIUM6.1Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-28313MEDIUM6.1Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
CVE-2023-28312MEDIUM6.5Azure Machine Learning Information Disclosure Vulnerability
CVE-2023-28311HIGH7.8Microsoft Word Remote Code Execution Vulnerability
CVE-2023-28309MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now