2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40545CRITICAL9.8Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 ver...
CVE-2023-47618HIGH7.2A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada ...
CVE-2023-47617HIGH7.2A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Oma...
CVE-2023-47209HIGH7.2A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada G...
CVE-2023-47167HIGH7.2A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gig...
CVE-2023-46683HIGH7.2A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Lin...
CVE-2023-43482HIGH7.2A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router ...
CVE-2023-42664HIGH7.2A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER...
CVE-2023-36498HIGH7.2A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gi...
CVE-2023-50395HIGH8 SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This ...
CVE-2023-46183MEDIUM4.4IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could all...
CVE-2023-35188HIGH8 SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This v...
CVE-2023-5584Rejected reason: We have rejected this CVE as it was determined a non-security issue by the vendor.
CVE-2023-4503HIGH7.5An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP serv...
CVE-2023-32479HIGH7.8 Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 ...
CVE-2023-32474MEDIUM6.6 Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount p...
CVE-2023-32454HIGH7.1 DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A l...
CVE-2023-32451HIGH7.8 Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malici...
CVE-2023-28063MEDIUM4.4 Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin...
CVE-2023-52239MEDIUM6.5The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.
CVE-2023-28049HIGH7.1 Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authentic...
CVE-2023-25543HIGH7.8 Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privi...
CVE-2023-43536HIGH7.5Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43535HIGH7.8Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
CVE-2023-43534CRITICAL9.8Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access po...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now