2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43544HIGH7.8Memory corruption when IPC callback handle is used after it has been released during register callback by another thread...
CVE-2023-43543HIGH7Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of...
CVE-2023-43542HIGH7.8Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2023-43538HIGH7.8Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
CVE-2023-43537HIGH7.5Information disclosure while handling T2LM Action Frame in WLAN Host.
CVE-2023-48789MEDIUM6.5A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker t...
CVE-2023-51436MEDIUM5.9Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote aut...
CVE-2023-42427MEDIUM6.5Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote aut...
CVE-2023-6382MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2023-46810HIGH7.3A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileg...
CVE-2023-38551HIGH8.2A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inje...
CVE-2023-38042HIGH7.8A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to ex...
CVE-2023-7073MEDIUM6.4The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all v...
CVE-2023-52882MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX ra...
CVE-2023-46297MEDIUM5.1An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin ...
CVE-2023-42005HIGH8.8IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a use...
CVE-2023-52881MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This...
CVE-2023-6743HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code...
CVE-2023-30314MEDIUM6.5An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could...
CVE-2023-30312HIGH7.3An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, ...
CVE-2023-46694HIGH8.1Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote co...
CVE-2023-30313HIGH7.5An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial ...
CVE-2023-30310HIGH7.5An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a de...
CVE-2023-30309MEDIUM5.7An issue discovered in D-Link DI-7003GV2 routers allows attackers to hijack TCP sessions which could lead to a denial of...
CVE-2023-30308MEDIUM6.5An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hija...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now