2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-32079HIGH8.8Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6...
CVE-2023-32078HIGH7.5Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions p...
CVE-2023-32077HIGH7.5Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in N...
CVE-2023-4420HIGH7.4A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo...
CVE-2023-4419HIGH8.8The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure...
CVE-2023-4418HIGH7.5A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-ba...
CVE-2023-31412HIGH7.5The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to ret...
CVE-2023-40710HIGH7.5An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests...
CVE-2023-40709HIGH7.5An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-...
CVE-2023-40707HIGH7.5There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version ...
CVE-2023-34971HIGH8.8An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vu...
CVE-2023-34040HIGH7.8In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector e...
CVE-2023-3705HIGH7.5The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the a...
CVE-2023-4513HIGH7.5BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injecti...
CVE-2023-4512HIGH7.5CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
CVE-2023-4511HIGH7.5BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injec...
CVE-2023-40573HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports ...
CVE-2023-40572HIGH8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create acti...
CVE-2023-32559HIGH7.5A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x...
CVE-2023-41028HIGH8.8A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticat...
CVE-2023-3453HIGH8.1 ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allo...
CVE-2023-38422HIGH7.5Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the manage...
CVE-2023-32202HIGH8.8Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are st...
CVE-2023-40185HIGH8.6shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded...
CVE-2023-40177HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now