2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38264HIGH7.5The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21...
CVE-2023-37526MEDIUM6.5HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnera...
CVE-2023-29881MEDIUM6.5phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.
CVE-2023-26863Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-26566HIGH8.6Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which a...
CVE-2023-41651MEDIUM6.5Missing Authorization vulnerability in Multi-column Tag Map.This issue affects Multi-column Tag Map: from n/a through 17...
CVE-2023-40490HIGH7.8Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2023-37325MEDIUM5.4D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attac...
CVE-2023-35757HIGH8.8D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulne...
CVE-2023-35749HIGH8.8D-Link DAP-2622 DDP Firmware Upgrade Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2023-35748HIGH8.8D-Link DAP-2622 DDP Firmware Upgrade Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability...
CVE-2023-27321HIGH7.5OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability...
CVE-2023-40694MEDIUM5.5IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read...
CVE-2023-42757MEDIUM4.2Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by...
CVE-2023-46012CRITICAL9.8Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP...
CVE-2023-7240MEDIUM5.8 An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Reques...
CVE-2023-31234MEDIUM6.3Missing Authorization vulnerability in Tilda Publishing.This issue affects Tilda Publishing: from n/a through 0.3.23.
CVE-2023-6810MEDIUM4.3The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improp...
CVE-2023-33548MEDIUM6.8Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 al...
CVE-2023-43531HIGH7.8Memory corruption while verifying the serialized header when the key pairs are generated.
CVE-2023-43530HIGH7.8Memory corruption in HLOS while checking for the storage type.
CVE-2023-43529HIGH7.5Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
CVE-2023-43528MEDIUM5.5Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is...
CVE-2023-43527MEDIUM5.5Information disclosure while parsing dts header atom in Video.
CVE-2023-43526HIGH7.8Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now