2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28097 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SI... |
| CVE-2023-24468 | CRITICAL | 9.8 | 0.9% | Mar 15, 2023 | Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 |
| CVE-2023-1421 | MEDIUM | 6.1 | 0.4% | Mar 15, 2023 | A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker t... |
| CVE-2023-1389 | HIGH | 8.8 | 100.0% | Mar 15, 2023 | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i... |
| CVE-2023-28096 | HIGH | 7.5 | 0.8% | Mar 15, 2023 | OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and pr... |
| CVE-2023-28095 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potentia... |
| CVE-2023-27601 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash... |
| CVE-2023-27600 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash... |
| CVE-2023-25267 | HIGH | 8.8 | 1.0% | Mar 15, 2023 | An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in ... |
| CVE-2023-28450 | HIGH | 7.5 | 1.3% | Mar 15, 2023 | An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be... |
| CVE-2023-27599 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the funct... |
| CVE-2023-27598 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malf... |
| CVE-2023-27597 | HIGH | 7.5 | 0.7% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, when a special... |
| CVE-2023-27596 | HIGH | 7.5 | 0.7% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crash... |
| CVE-2023-26484 | HIGH | 8.2 | 0.6% | Mar 15, 2023 | KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has ta... |
| CVE-2023-22591 | LOW | 3.2 | 0.2% | Mar 15, 2023 | IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access t... |
| CVE-2023-26912 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb ... |
| CVE-2023-25680 | MEDIUM | 6.5 | 0.6% | Mar 15, 2023 | IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Pro... |
| CVE-2023-25345 | HIGH | 7.5 | 1.0% | Mar 15, 2023 | Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary f... |
| CVE-2023-25344 | CRITICAL | 9.8 | 1.0% | Mar 15, 2023 | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via... |
| CVE-2023-25282 | MEDIUM | 6.5 | 1.0% | Mar 15, 2023 | A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.... |
| CVE-2023-22876 | MEDIUM | 6.5 | 0.5% | Mar 15, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privilege... |
| CVE-2023-26284 | HIGH | 8.8 | 0.7% | Mar 15, 2023 | IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the ... |
| CVE-2023-25804 | MEDIUM | 5.3 | 0.8% | Mar 15, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a... |
| CVE-2023-24229 | HIGH | 7.8 | 6.7% | Mar 15, 2023 | DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to injec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now