2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-41031HIGH8.8Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authentic...
CVE-2023-41029HIGH8.8Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1...
CVE-2023-41027HIGH8.8Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 an...
CVE-2023-5002HIGH8.8A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to ext...
CVE-2023-34319HIGH7.8The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that...
CVE-2023-43784HIGH7.5Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE...
CVE-2023-43783HIGH7.5Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if...
CVE-2023-43767HIGH7.5Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Clien...
CVE-2023-43766HIGH7.8Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure...
CVE-2023-43765HIGH7.5Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, ...
CVE-2023-43761HIGH7.5Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSec...
CVE-2023-43760HIGH7.5Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, ...
CVE-2023-23362HIGH8.8An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit...
CVE-2023-31718HIGH7.5FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
CVE-2023-31717HIGH7.5A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
CVE-2023-31716HIGH7.5FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
CVE-2023-5068HIGH7.8Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file....
CVE-2023-4504HIGH7Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are sus...
CVE-2023-42261HIGH7.5Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is th...
CVE-2023-38343HIGH7.5An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022...
CVE-2023-42482HIGH7.5Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.
CVE-2023-42280HIGH7.5mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not v...
CVE-2023-41993HIGH8.8The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to...
CVE-2023-41992HIGH7.8The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO...
CVE-2023-42805HIGH7.5quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QU...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now