2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0468MEDIUM4.7A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Ker...
CVE-2023-0463LOW3.3The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manag...
CVE-2023-0452MEDIUM5.3Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configura...
CVE-2023-0451HIGH7.5Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certai...
CVE-2023-0449Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-0448MEDIUM6.1The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resultin...
CVE-2023-0444HIGH8.8A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'Use...
CVE-2023-0417MEDIUM6.5Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet...
CVE-2023-0416MEDIUM6.5GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or...
CVE-2023-0415MEDIUM6.5iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ...
CVE-2023-0414MEDIUM6.5Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture ...
CVE-2023-0413MEDIUM6.5Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ...
CVE-2023-0412HIGH7.1TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection o...
CVE-2023-0411MEDIUM6.5Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via ...
CVE-2023-0394MEDIUM5.5A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in ...
CVE-2023-0356HIGH7.5 SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which ...
CVE-2023-0321CRITICAL9.1Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration fil...
CVE-2023-0284HIGH8.1Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipul...
CVE-2023-0229MEDIUM6.3A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue t...
CVE-2023-0396MEDIUM6.8A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command r...
CVE-2023-23331CRITICAL9.8Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
CVE-2023-22485MEDIUM5.3cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29...
CVE-2023-21796HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-21795HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-21775HIGH8.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now