2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40458HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially all...
CVE-2023-48952HIGH7.5An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den...
CVE-2023-48951HIGH7.5An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service...
CVE-2023-48950HIGH7.5An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2023-48949HIGH7.5An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48948HIGH7.5An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48947HIGH7.5An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48946HIGH7.5An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (...
CVE-2023-48945HIGH7.5A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted...
CVE-2023-49083HIGH7.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pe...
CVE-2023-49079HIGH7.5Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary ...
CVE-2023-6218HIGH7.2 In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privi...
CVE-2023-49673HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier all...
CVE-2023-49655HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have J...
CVE-2023-40626HIGH7.5The language file parsing process could be manipulated to expose environment variables. Environment variables might cont...
CVE-2023-6378HIGH7.5A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount ...
CVE-2023-6351HIGH8.8Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap...
CVE-2023-6350HIGH8.8Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap...
CVE-2023-6348HIGH8.8Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the ...
CVE-2023-6347HIGH8.8Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap co...
CVE-2023-6346HIGH8.8Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit hea...
CVE-2023-46887HIGH7.5In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
CVE-2023-24294HIGH7.5Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component Netlin...
CVE-2023-46944HIGH7.8An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis...
CVE-2023-45539HIGH8.2HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive info...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now