2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40597HIGH8.8In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to...
CVE-2023-40596HIGH8.8In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk...
CVE-2023-40595HIGH8.8In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query tha...
CVE-2023-40594HIGH7.5In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perf...
CVE-2023-40593HIGH7.5In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion mar...
CVE-2023-20266HIGH7.2A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communica...
CVE-2023-41539HIGH7.5phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
CVE-2023-38975HIGH7.5* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_ve...
CVE-2023-4572HIGH8.8Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit ...
CVE-2023-4346HIGH7.5 KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable...
CVE-2023-39663HIGH7.5Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJ...
CVE-2023-20890HIGH7.2Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with admin...
CVE-2023-3646HIGH7.5On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error ma...
CVE-2023-39616HIGH7.5AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p...
CVE-2023-41376HIGH7.5Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enab...
CVE-2023-41362HIGH7.2MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use ...
CVE-2023-38802HIGH7.5FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a craft...
CVE-2023-23774HIGH8.4Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller expos...
CVE-2023-23773HIGH8.8Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic sig...
CVE-2023-23772HIGH8.8Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks crypt...
CVE-2023-23771HIGH8.4Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI),...
CVE-2023-32457HIGH8.8 Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote atta...
CVE-2023-41358HIGH7.5An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
CVE-2023-1995HIGH7.5Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data ...
CVE-2023-41005HIGH7.8An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateA...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now