2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52356 | HIGH | 7.5 | 2.2% | Jan 25, 2024 | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadR... |
| CVE-2023-52355 | HIGH | 7.5 | 1.7% | Jan 25, 2024 | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanl... |
| CVE-2023-41474 | MEDIUM | 6.5 | 37.6% | Jan 25, 2024 | Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensiti... |
| CVE-2023-7227 | CRITICAL | 9.8 | 1.3% | Jan 25, 2024 | SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the ... |
| CVE-2023-6267 | CRITICAL | 9.8 | 0.7% | Jan 25, 2024 | A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that... |
| CVE-2023-52076 | HIGH | 7.8 | 1.0% | Jan 25, 2024 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arb... |
| CVE-2023-40547 | HIGH | 8.3 | 4.9% | Jan 25, 2024 | A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when pa... |
| CVE-2023-3181 | HIGH | 7.8 | 0.2% | Jan 25, 2024 | The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~n... |
| CVE-2023-6282 | MEDIUM | 6.1 | 0.3% | Jan 25, 2024 | IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerab... |
| CVE-2023-33760 | MEDIUM | 5.3 | 0.3% | Jan 25, 2024 | SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow a... |
| CVE-2023-33759 | CRITICAL | 9.8 | 0.8% | Jan 25, 2024 | SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to ... |
| CVE-2023-33758 | MEDIUM | 6.1 | 0.4% | Jan 25, 2024 | Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via th... |
| CVE-2023-33757 | MEDIUM | 5.9 | 0.3% | Jan 25, 2024 | A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Andr... |
| CVE-2023-50785 | LOW | 2.7 | 2.0% | Jan 25, 2024 | Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal. |
| CVE-2023-24676 | HIGH | 7.2 | 1.3% | Jan 24, 2024 | An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the dow... |
| CVE-2023-52040 | CRITICAL | 9.8 | 0.9% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_412... |
| CVE-2023-52039 | CRITICAL | 9.8 | 0.8% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415... |
| CVE-2023-52038 | CRITICAL | 9.8 | 0.8% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415... |
| CVE-2023-51890 | HIGH | 7.5 | 0.9% | Jan 24, 2024 | An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via craf... |
| CVE-2023-51889 | CRITICAL | 9.8 | 1.3% | Jan 24, 2024 | Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute... |
| CVE-2023-51888 | HIGH | 7.5 | 0.8% | Jan 24, 2024 | Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a ... |
| CVE-2023-51887 | CRITICAL | 9.8 | 2.5% | Jan 24, 2024 | Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via craf... |
| CVE-2023-51886 | HIGH | 7.5 | 0.8% | Jan 24, 2024 | Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a deni... |
| CVE-2023-51885 | CRITICAL | 9.8 | 1.3% | Jan 24, 2024 | Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the le... |
| CVE-2023-44281 | HIGH | 7.1 | 0.2% | Jan 24, 2024 | Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now