2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-38615HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to exe...
CVE-2023-35793HIGH8.8An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vuln...
CVE-2023-35074HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and...
CVE-2023-32541HIGH7.8A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially ...
CVE-2023-32396HIGH7.8This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 1...
CVE-2023-32377HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may ...
CVE-2023-2315HIGH8.8Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the ...
CVE-2023-28055HIGH8.8 Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated at...
CVE-2023-0456HIGH7.5A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro...
CVE-2023-4259HIGH8.8Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
CVE-2023-43278HIGH8.8A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an ad...
CVE-2023-38907HIGH7.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-42753HIGH7.8An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to ...
CVE-2023-43642HIGH7.5snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream ...
CVE-2023-40581HIGH7.8yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to...
CVE-2023-4156HIGH7.1A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be u...
CVE-2023-5165HIGH8.8Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t...
CVE-2023-5156HIGH7.5A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which ...
CVE-2023-4300HIGH7.2The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing ...
CVE-2023-4238HIGH7.2The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could all...
CVE-2023-43382HIGH8.8Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via...
CVE-2023-3664HIGH7.2The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site a...
CVE-2023-3550HIGH7.3Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML f...
CVE-2023-3547HIGH8.8The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several action...
CVE-2023-32653HIGH8.8An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A spe...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now