2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-39620HIGH7.5An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitiv...
CVE-2023-37377HIGH7.5An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, ...
CVE-2023-37368HIGH7.5An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Au...
CVE-2023-40271HIGH7.5In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell P...
CVE-2023-36184HIGH7.5CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.
CVE-2023-4685HIGH7.8Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffe...
CVE-2023-4528HIGH7.2Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker t...
CVE-2023-41064HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1...
CVE-2023-41061HIGH7.8A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1...
CVE-2023-40060HIGH7.2A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass m...
CVE-2023-30800HIGH7.5The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthent...
CVE-2023-39424HIGH8.8A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to u...
CVE-2023-39421HIGH7.7The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for thir...
CVE-2023-39420HIGH8.8The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customer...
CVE-2023-39240HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is c...
CVE-2023-39239HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused...
CVE-2023-39238HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation ...
CVE-2023-4815HIGH8.8Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
CVE-2023-39237HIGH8.8 ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attac...
CVE-2023-39236HIGH8.8 ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker ...
CVE-2023-38033HIGH8.8 ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remo...
CVE-2023-38032HIGH8.8 ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacke...
CVE-2023-38031HIGH8.8 ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker wi...
CVE-2023-34357HIGH7.8 Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent o...
CVE-2023-38616HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13.5. An app may be ab...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now