2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24169CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
CVE-2023-24167CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
CVE-2023-24166CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
CVE-2023-24165CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
CVE-2023-24164CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
CVE-2023-24057HIGH8.1HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via d...
CVE-2023-24054Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-24022CRITICAL9.8Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded c...
CVE-2023-23951MEDIUM6.1Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
CVE-2023-23950MEDIUM6.1User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
CVE-2023-23949MEDIUM5.4An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
CVE-2023-23619HIGH8.8Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Ve...
CVE-2023-23614HIGH8.8Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and ab...
CVE-2023-23613MEDIUM6.5OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implem...
CVE-2023-23612HIGH8.8OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained f...
CVE-2023-23611MEDIUM5.4LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provid...
CVE-2023-23610MEDIUM6.5GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper ...
CVE-2023-23609HIGH7.4Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and inc...
CVE-2023-23608MEDIUM4.3Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is pas...
CVE-2023-23151MEDIUM6.5bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_co...
CVE-2023-22971MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, ...
CVE-2023-22739MEDIUM6.5Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and...
CVE-2023-22736HIGH8.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, pr...
CVE-2023-22725MEDIUM4.8GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cro...
CVE-2023-22724MEDIUM4.8GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting vi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now