2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40545 | CRITICAL | 9.8 | 0.9% | Feb 6, 2024 | Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 ver... |
| CVE-2023-47618 | HIGH | 7.2 | 1.9% | Feb 6, 2024 | A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada ... |
| CVE-2023-47617 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Oma... |
| CVE-2023-47209 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada G... |
| CVE-2023-47167 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gig... |
| CVE-2023-46683 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Lin... |
| CVE-2023-43482 | HIGH | 7.2 | 3.3% | Feb 6, 2024 | A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router ... |
| CVE-2023-42664 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER... |
| CVE-2023-36498 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gi... |
| CVE-2023-50395 | HIGH | 8 | 1.6% | Feb 6, 2024 | SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This ... |
| CVE-2023-46183 | MEDIUM | 4.4 | 0.2% | Feb 6, 2024 | IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could all... |
| CVE-2023-35188 | HIGH | 8 | 1.5% | Feb 6, 2024 | SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This v... |
| CVE-2023-5584 | — | — | — | Feb 6, 2024 | Rejected reason: We have rejected this CVE as it was determined a non-security issue by the vendor. |
| CVE-2023-4503 | HIGH | 7.5 | 0.7% | Feb 6, 2024 | An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP serv... |
| CVE-2023-32479 | HIGH | 7.8 | 0.1% | Feb 6, 2024 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 ... |
| CVE-2023-32474 | MEDIUM | 6.6 | 0.2% | Feb 6, 2024 | Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount p... |
| CVE-2023-32454 | HIGH | 7.1 | 0.2% | Feb 6, 2024 | DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A l... |
| CVE-2023-32451 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malici... |
| CVE-2023-28063 | MEDIUM | 4.4 | 0.2% | Feb 6, 2024 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin... |
| CVE-2023-52239 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport. |
| CVE-2023-28049 | HIGH | 7.1 | 0.1% | Feb 6, 2024 | Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authentic... |
| CVE-2023-25543 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privi... |
| CVE-2023-43536 | HIGH | 7.5 | 0.3% | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. |
| CVE-2023-43535 | HIGH | 7.8 | 0.1% | Feb 6, 2024 | Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger. |
| CVE-2023-43534 | CRITICAL | 9.8 | 0.3% | Feb 6, 2024 | Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access po... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now