2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-52356HIGH7.5A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadR...
CVE-2023-52355HIGH7.5An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanl...
CVE-2023-41474MEDIUM6.5Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensiti...
CVE-2023-7227CRITICAL9.8 SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the ...
CVE-2023-6267CRITICAL9.8A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that...
CVE-2023-52076HIGH7.8Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arb...
CVE-2023-40547HIGH8.3A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when pa...
CVE-2023-3181HIGH7.8The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~n...
CVE-2023-6282MEDIUM6.1IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerab...
CVE-2023-33760MEDIUM5.3SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow a...
CVE-2023-33759CRITICAL9.8SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to ...
CVE-2023-33758MEDIUM6.1Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via th...
CVE-2023-33757MEDIUM5.9A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Andr...
CVE-2023-50785LOW2.7Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
CVE-2023-24676HIGH7.2An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the dow...
CVE-2023-52040CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_412...
CVE-2023-52039CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415...
CVE-2023-52038CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415...
CVE-2023-51890HIGH7.5An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via craf...
CVE-2023-51889CRITICAL9.8Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute...
CVE-2023-51888HIGH7.5Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a ...
CVE-2023-51887CRITICAL9.8Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via craf...
CVE-2023-51886HIGH7.5Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a deni...
CVE-2023-51885CRITICAL9.8Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the le...
CVE-2023-44281HIGH7.1 Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now