2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40458 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially all... |
| CVE-2023-48952 | HIGH | 7.5 | 1.0% | Nov 29, 2023 | An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den... |
| CVE-2023-48951 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service... |
| CVE-2023-48950 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2023-48949 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48948 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48947 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48946 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (... |
| CVE-2023-48945 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted... |
| CVE-2023-49083 | HIGH | 7.5 | 1.0% | Nov 29, 2023 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pe... |
| CVE-2023-49079 | HIGH | 7.5 | 0.4% | Nov 29, 2023 | Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary ... |
| CVE-2023-6218 | HIGH | 7.2 | 0.7% | Nov 29, 2023 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privi... |
| CVE-2023-49673 | HIGH | 8.8 | 0.4% | Nov 29, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier all... |
| CVE-2023-49655 | HIGH | 8.8 | 0.4% | Nov 29, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have J... |
| CVE-2023-40626 | HIGH | 7.5 | 0.8% | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might cont... |
| CVE-2023-6378 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount ... |
| CVE-2023-6351 | HIGH | 8.8 | 0.9% | Nov 29, 2023 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6350 | HIGH | 8.8 | 1.1% | Nov 29, 2023 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6348 | HIGH | 8.8 | 1.0% | Nov 29, 2023 | Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the ... |
| CVE-2023-6347 | HIGH | 8.8 | 1.1% | Nov 29, 2023 | Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap co... |
| CVE-2023-6346 | HIGH | 8.8 | 1.0% | Nov 29, 2023 | Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit hea... |
| CVE-2023-46887 | HIGH | 7.5 | 0.3% | Nov 29, 2023 | In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability. |
| CVE-2023-24294 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component Netlin... |
| CVE-2023-46944 | HIGH | 7.8 | 1.2% | Nov 28, 2023 | An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis... |
| CVE-2023-45539 | HIGH | 8.2 | 1.5% | Nov 28, 2023 | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive info... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now