2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43544 | HIGH | 7.8 | 0.1% | Jun 3, 2024 | Memory corruption when IPC callback handle is used after it has been released during register callback by another thread... |
| CVE-2023-43543 | HIGH | 7 | 0.1% | Jun 3, 2024 | Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of... |
| CVE-2023-43542 | HIGH | 7.8 | 0.1% | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. |
| CVE-2023-43538 | HIGH | 7.8 | 0.1% | Jun 3, 2024 | Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. |
| CVE-2023-43537 | HIGH | 7.5 | 0.2% | Jun 3, 2024 | Information disclosure while handling T2LM Action Frame in WLAN Host. |
| CVE-2023-48789 | MEDIUM | 6.5 | 0.5% | Jun 3, 2024 | A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker t... |
| CVE-2023-51436 | MEDIUM | 5.9 | 0.2% | Jun 3, 2024 | Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote aut... |
| CVE-2023-42427 | MEDIUM | 6.5 | 0.3% | Jun 3, 2024 | Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote aut... |
| CVE-2023-6382 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2023-46810 | HIGH | 7.3 | 0.3% | May 31, 2024 | A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileg... |
| CVE-2023-38551 | HIGH | 8.2 | 1.0% | May 31, 2024 | A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inje... |
| CVE-2023-38042 | HIGH | 7.8 | 0.3% | May 31, 2024 | A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to ex... |
| CVE-2023-7073 | MEDIUM | 6.4 | 0.3% | May 31, 2024 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all v... |
| CVE-2023-52882 | MEDIUM | 5.5 | 0.3% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX ra... |
| CVE-2023-46297 | MEDIUM | 5.1 | 0.2% | May 29, 2024 | An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin ... |
| CVE-2023-42005 | HIGH | 8.8 | 0.3% | May 29, 2024 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a use... |
| CVE-2023-52881 | MEDIUM | 5.5 | 0.2% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This... |
| CVE-2023-6743 | HIGH | 8.8 | 1.3% | May 29, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code... |
| CVE-2023-30314 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could... |
| CVE-2023-30312 | HIGH | 7.3 | 0.3% | May 28, 2024 | An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, ... |
| CVE-2023-46694 | HIGH | 8.1 | 0.9% | May 28, 2024 | Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote co... |
| CVE-2023-30313 | HIGH | 7.5 | 0.4% | May 28, 2024 | An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial ... |
| CVE-2023-30310 | HIGH | 7.5 | 0.4% | May 28, 2024 | An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a de... |
| CVE-2023-30309 | MEDIUM | 5.7 | 0.3% | May 28, 2024 | An issue discovered in D-Link DI-7003GV2 routers allows attackers to hijack TCP sessions which could lead to a denial of... |
| CVE-2023-30308 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hija... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now