2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-49952HIGH7.5Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
CVE-2023-39180HIGH7.5A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releas...
CVE-2023-39179HIGH7.5A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack o...
CVE-2023-39176HIGH7.5A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue ...
CVE-2023-4639HIGH7.4A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requ...
CVE-2023-20154HIGH8.1A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote a...
CVE-2023-20125HIGH8.6A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacke...
CVE-2023-4458HIGH7.5A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o...
CVE-2023-35686HIGH7.8In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This...
CVE-2023-35659HIGH7.8In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the...
CVE-2023-50176HIGH8.8A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allo...
CVE-2023-47543HIGH8.1An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 throug...
CVE-2023-32736HIGH7.3A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMAT...
CVE-2023-1973HIGH7.5A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of ...
CVE-2023-29126HIGH8.8The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force pro...
CVE-2023-29125HIGH8A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
CVE-2023-29121HIGH8.8Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
CVE-2023-29120HIGH8.8Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv...
CVE-2023-29119HIGH8.8Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.ph...
CVE-2023-29118HIGH8.8Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.p...
CVE-2023-29117HIGH8.8Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox...
CVE-2023-52066HIGH7.2http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.
CVE-2023-50310HIGH7.5IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses ...
CVE-2023-6080HIGH7.8Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnera...
CVE-2023-49570HIGH7.4A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now