2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-23651HIGH8.8Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
CVE-2023-45047HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.
CVE-2023-32724HIGH8.8Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory ...
CVE-2023-32722HIGH7.8The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
CVE-2023-40829HIGH7.5There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5...
CVE-2023-1943HIGH8.8Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
CVE-2023-5476HIGH8.8Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit...
CVE-2023-5474HIGH8.8Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to en...
CVE-2023-5218HIGH8.8Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploi...
CVE-2023-39325HIGH7.5A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource...
CVE-2023-44186HIGH7.5 An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Jun...
CVE-2023-3781HIGH7.8there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with ...
CVE-2023-5535HIGH7.8Use After Free in GitHub repository vim/vim prior to v9.0.2010.
CVE-2023-43661HIGH8.8Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to crea...
CVE-2023-40142HIGH7.8In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead ...
CVE-2023-40141HIGH7.8In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check...
CVE-2023-35661HIGH7.5In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds che...
CVE-2023-35652HIGH7.5In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a...
CVE-2023-35649HIGH7.2In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2023-44961HIGH7.5SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive i...
CVE-2023-38817HIGH7.8An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to th...
CVE-2023-43960HIGH8.8An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in...
CVE-2023-23930HIGH7.2vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known se...
CVE-2023-35194HIGH8.8An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v...
CVE-2023-35193HIGH8.8An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now