2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22656LOW3.9Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authentica...
CVE-2023-47717MEDIUM4.4IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of ...
CVE-2023-48643CRITICAL9.8Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allo...
CVE-2023-46842MEDIUM6.5Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that the...
CVE-2023-40297HIGH7.5Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.
CVE-2023-7258MEDIUM6.5A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead t...
CVE-2023-5938HIGH8.9Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable ...
CVE-2023-5937MEDIUM5.2On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosur...
CVE-2023-5936HIGH7.8On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a mali...
CVE-2023-5935HIGH7.4When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process....
CVE-2023-6324HIGH8.8ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
CVE-2023-6323MEDIUM6.5ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an autho...
CVE-2023-6322HIGH8.8A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE ver...
CVE-2023-6321HIGH8.8A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to ...
CVE-2023-33327HIGH8.8Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This is...
CVE-2023-50180MEDIUM5.5An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC versio...
CVE-2023-46714HIGH7.2A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 ...
CVE-2023-45586MEDIUM5An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode versio...
CVE-2023-45583HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, Forti...
CVE-2023-44247HIGH7.2A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker...
CVE-2023-40720HIGH7.1An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug...
CVE-2023-36640MEDIUM6.7A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, Forti...
CVE-2023-24204MEDIUM5.4SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to exe...
CVE-2023-24203MEDIUM5.4Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker...
CVE-2023-6812MEDIUM6.1The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now