2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25669HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and windo...
CVE-2023-25668CRITICAL9.8TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can acc...
CVE-2023-25667HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs...
CVE-2023-25666HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating poi...
CVE-2023-25665HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaxim...
CVE-2023-25664CRITICAL9.8TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer ...
CVE-2023-25663HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_contain...
CVE-2023-25662HIGH7.5TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to intege...
CVE-2023-25660HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `sum...
CVE-2023-25659HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indic...
CVE-2023-25658HIGH7.5TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read i...
CVE-2023-27042HIGH8.8Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
CVE-2023-23149CRITICAL9.8DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.
CVE-2023-28150CRITICAL9.8An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection ...
CVE-2023-27055HIGH7.5Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.
CVE-2023-26864CRITICAL9.8SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to g...
CVE-2023-1583MEDIUM5.5A NULL pointer dereference was found in io_file_bitmap_get in io_uring/filetable.c in the io_uring sub-component in the ...
CVE-2023-28435MEDIUM6.1Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not ch...
CVE-2023-28448HIGH7.5Versionize is a framework for version tolerant serializion/deserialization of Rust data structures, designed for usecase...
CVE-2023-28446HIGH8.8Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary p...
CVE-2023-28444HIGH7.5angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker contain...
CVE-2023-28151CRITICAL9.8An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) in...
CVE-2023-25350HIGH8.8Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgmen...
CVE-2023-22812HIGH7.4SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to ma...
CVE-2023-21079MEDIUM6.7In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a heap buffer overflow. This could ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now