2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-41121HIGH7.5Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash thro...
CVE-2023-39289HIGH7.5A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an un...
CVE-2023-34723HIGH7.5An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information ...
CVE-2023-40586HIGH7.5OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`,...
CVE-2023-40585HIGH7.5ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is...
CVE-2023-40583HIGH7.5libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to ...
CVE-2023-40031HIGH7.8Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write ove...
CVE-2023-37249HIGH8.8Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell...
CVE-2023-36199HIGH7.5An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGene...
CVE-2023-36198HIGH7.5Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the ...
CVE-2023-24621HIGH7.8An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by defau...
CVE-2023-40798HIGH8.8In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input pa...
CVE-2023-40797HIGH8.8In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting i...
CVE-2023-40796HIGH7.8Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
CVE-2023-40915HIGH7.5Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This v...
CVE-2023-40801HIGH8.8The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerabilit...
CVE-2023-40800HIGH8.8The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication ...
CVE-2023-4478HIGH8.2Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to re...
CVE-2023-25649HIGH8.8 There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_D...
CVE-2023-32756HIGH7.5 e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An ...
CVE-2023-41173HIGH7.5AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
CVE-2023-40599HIGH7.5Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which ...
CVE-2023-40022HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to ...
CVE-2023-40017HIGH7.5GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In ...
CVE-2023-37469HIGH8.8CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now