2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-21418HIGH7.1Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to pat...
CVE-2023-21417HIGH7.1Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnera...
CVE-2023-45886HIGH7.5The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending...
CVE-2023-48310HIGH7.5TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere...
CVE-2023-48051HIGH7.5An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption pad...
CVE-2023-48192HIGH7.8An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracero...
CVE-2023-47172HIGH7.8Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Ser...
CVE-2023-48111HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentContro...
CVE-2023-48110HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControl...
CVE-2023-48109HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentCon...
CVE-2023-4824HIGH8.8The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow atta...
CVE-2023-48293HIGH8.8The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-si...
CVE-2023-38885HIGH8.8OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole ap...
CVE-2023-38884HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows ...
CVE-2023-38879HIGH7.5The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a direc...
CVE-2023-48292HIGH8.8The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior ...
CVE-2023-48241HIGH7.5XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, a...
CVE-2023-48240HIGH8.8XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a...
CVE-2023-48221HIGH8.8wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to ver...
CVE-2023-6196HIGH8.8The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2023-48090HIGH7.1GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.
CVE-2023-6045HIGH7.8in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through t...
CVE-2023-5593HIGH7.8The out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could al...
CVE-2023-43612HIGH7.8in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservat...
CVE-2023-3116HIGH7.1in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now