2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49768MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Dre...
CVE-2023-47843HIGH7.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zachary Segal CataBlog.T...
CVE-2023-3675MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web...
CVE-2023-41864MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF...
CVE-2023-49742CRITICAL9.9Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
CVE-2023-4509MEDIUM4.3It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
CVE-2023-4235HIGH8.1A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive...
CVE-2023-4234HIGH8.1A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit...
CVE-2023-4233HIGH8.1A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_ad...
CVE-2023-4232HIGH8.1A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status...
CVE-2023-5407MEDIUM5.9Controller denial of service due to improper handling of a specially crafted message received by the controller. See Ho...
CVE-2023-5406MEDIUM5.9Server communication with a controller can lead to remote code execution using a specially crafted message from the cont...
CVE-2023-5405MEDIUM5.9Server information leak for the CDA Server process memory can occur when an error is generated in response to a speciall...
CVE-2023-5404HIGH8.1Server receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution o...
CVE-2023-5403HIGH8.1Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution ...
CVE-2023-5401HIGH8.1Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability ...
CVE-2023-5400HIGH8.1Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability w...
CVE-2023-5398MEDIUM5.9Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. Se...
CVE-2023-5397HIGH8.1Server receiving a malformed message to create a new connection could lead to an attacker performing remote code executi...
CVE-2023-5396HIGH7.4Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in poss...
CVE-2023-5395HIGH8.1Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in...
CVE-2023-52645MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd ...
CVE-2023-46060HIGH7.5A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the p...
CVE-2023-6805MEDIUM6.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-45744HIGH8.8A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Rea...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now