2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22657 | HIGH | 7.8 | 0.4% | Feb 1, 2023 | On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F... |
| CVE-2023-22422 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforceme... |
| CVE-2023-22418 | MEDIUM | 6.1 | 0.3% | Feb 1, 2023 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versio... |
| CVE-2023-22374 | HIGH | 8.5 | 72.6% | Feb 1, 2023 | A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP ... |
| CVE-2023-22358 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windo... |
| CVE-2023-22341 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the fol... |
| CVE-2023-22340 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, whe... |
| CVE-2023-22326 | MEDIUM | 4.9 | 0.5% | Feb 1, 2023 | In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a... |
| CVE-2023-22323 | HIGH | 7.5 | 0.7% | Feb 1, 2023 | In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a... |
| CVE-2023-22302 | MEDIUM | 5.9 | 0.5% | Feb 1, 2023 | In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is ... |
| CVE-2023-22283 | MEDIUM | 6.5 | 0.2% | Feb 1, 2023 | On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Win... |
| CVE-2023-22281 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versio... |
| CVE-2023-0618 | HIGH | 7.5 | 0.9% | Feb 1, 2023 | A vulnerability was found in TRENDnet TEW-652BRP 3.04B01. It has been declared as critical. This vulnerability affects u... |
| CVE-2023-0617 | HIGH | 7.5 | 1.0% | Feb 1, 2023 | A vulnerability was found in TRENDNet TEW-811DRU 1.0.10.0. It has been classified as critical. This affects an unknown p... |
| CVE-2023-23136 | MEDIUM | 6.5 | 0.8% | Feb 1, 2023 | lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php. |
| CVE-2023-23135 | HIGH | 7.2 | 1.0% | Feb 1, 2023 | An arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafte... |
| CVE-2023-24997 | CRITICAL | 9.8 | 1.4% | Feb 1, 2023 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In... |
| CVE-2023-24610 | HIGH | 8.8 | 2.1% | Feb 1, 2023 | NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The... |
| CVE-2023-23132 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys. |
| CVE-2023-23131 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings. |
| CVE-2023-23130 | MEDIUM | 5.9 | 0.3% | Feb 1, 2023 | Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext... |
| CVE-2023-23128 | MEDIUM | 6.1 | 0.4% | Feb 1, 2023 | Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that... |
| CVE-2023-23127 | MEDIUM | 5.3 | 0.3% | Feb 1, 2023 | In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NO... |
| CVE-2023-23126 | MEDIUM | 6.1 | 0.4% | Feb 1, 2023 | Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users... |
| CVE-2023-22575 | HIGH | 8.8 | 0.6% | Feb 1, 2023 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in cel... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now