2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-38538MEDIUM5A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could ha...
CVE-2023-38537MEDIUM5.6A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incomi...
CVE-2023-3576MEDIUM5.5A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image fil...
CVE-2023-3428MEDIUM5.5A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local atta...
CVE-2023-27121MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasa...
CVE-2023-5371MEDIUM6.5RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection...
CVE-2023-5113MEDIUM6.1Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to W...
CVE-2023-4380MEDIUM6.3A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, th...
CVE-2023-3971MEDIUM5.4An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture c...
CVE-2023-40684MEDIUM5.4IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. T...
CVE-2023-40376MEDIUM6.5IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou...
CVE-2023-4497MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4496MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4495MEDIUM6.1Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr...
CVE-2023-4493MEDIUM5.4Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects m...
CVE-2023-4492MEDIUM6.1Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, mid...
CVE-2023-4090MEDIUM6.1Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tag...
CVE-2023-4037MEDIUM5.5Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local a...
CVE-2023-3153MEDIUM5.3A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al...
CVE-2023-5375MEDIUM6.1Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
CVE-2023-44272MEDIUM5.4A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant mes...
CVE-2023-5370MEDIUM5.5On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no spe...
CVE-2023-5368MEDIUM6.5On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional...
CVE-2023-30737MEDIUM5.5Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive...
CVE-2023-30736MEDIUM5.4Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute java...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now