2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-50342MEDIUM4.3HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certai...
CVE-2023-50348MEDIUM5.3HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error me...
CVE-2023-50346MEDIUM4.3HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application d...
CVE-2023-50345MEDIUM6.1HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to m...
CVE-2023-41779MEDIUM5.5There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an ...
CVE-2023-49558MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params functio...
CVE-2023-49557MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first fun...
CVE-2023-49556MEDIUM5.5Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_...
CVE-2023-49555MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in ...
CVE-2023-49554MEDIUM5.5Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_dir...
CVE-2023-50019MEDIUM5.9An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF ...
CVE-2023-4164MEDIUM5.5There is a possible information disclosure due to a missing permission check. This could lead to local information discl...
CVE-2023-45561MEDIUM5.3An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the ...
CVE-2023-51652MEDIUM6.1OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0,...
CVE-2023-7192MEDIUM4.4A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kerne...
CVE-2023-6693MEDIUM5.3A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virt...
CVE-2023-50333MEDIUM4.3Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing fre...
CVE-2023-48732MEDIUM4.3Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSoc...
CVE-2023-47858MEDIUM4.3Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of o...
CVE-2023-49135MEDIUM5.5 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released...
CVE-2023-48360MEDIUM5.5 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released...
CVE-2023-47857MEDIUM5.5 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released...
CVE-2023-47216MEDIUM5.5 in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources
CVE-2023-33037MEDIUM5.5Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
CVE-2023-33036MEDIUM5.5Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now