2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-21265HIGH7.5In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information d...
CVE-2023-40023HIGH7.5yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file incl...
CVE-2023-39908HIGH7.5The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations...
CVE-2023-28483HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write...
CVE-2023-28481HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any...
CVE-2023-38741HIGH7.5 IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement ...
CVE-2023-38721HIGH7.8The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. ...
CVE-2023-0872HIGH8The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple pl...
CVE-2023-33013HIGH8.8A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)...
CVE-2023-31041HIGH7.5An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information c...
CVE-2023-30188HIGH7.5Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a den...
CVE-2023-3160HIGH7.8 The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or...
CVE-2023-40303HIGH7.8GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions ...
CVE-2023-3267HIGH8.8When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. T...
CVE-2023-3263HIGH7.5The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the ...
CVE-2023-40296HIGH7.5async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when proce...
CVE-2023-40295HIGH8.8libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.
CVE-2023-3261HIGH7.2The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in th...
CVE-2023-3260HIGH8.8The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `us...
CVE-2023-40283HIGH7.8An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is ...
CVE-2023-40274HIGH7.5An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zol...
CVE-2023-39406HIGH7.5Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps ...
CVE-2023-39404HIGH7.5Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation o...
CVE-2023-39397HIGH7.5Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability ma...
CVE-2023-39395HIGH7.5Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnera...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now