2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21265 | HIGH | 7.5 | 0.3% | Aug 14, 2023 | In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information d... |
| CVE-2023-40023 | HIGH | 7.5 | 0.9% | Aug 14, 2023 | yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file incl... |
| CVE-2023-39908 | HIGH | 7.5 | 0.5% | Aug 14, 2023 | The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations... |
| CVE-2023-28483 | HIGH | 8.8 | 0.7% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write... |
| CVE-2023-28481 | HIGH | 8.8 | 0.6% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any... |
| CVE-2023-38741 | HIGH | 7.5 | 0.8% | Aug 14, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement ... |
| CVE-2023-38721 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. ... |
| CVE-2023-0872 | HIGH | 8 | 3.0% | Aug 14, 2023 | The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple pl... |
| CVE-2023-33013 | HIGH | 8.8 | 1.4% | Aug 14, 2023 | A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)... |
| CVE-2023-31041 | HIGH | 7.5 | 0.3% | Aug 14, 2023 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information c... |
| CVE-2023-30188 | HIGH | 7.5 | 1.8% | Aug 14, 2023 | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a den... |
| CVE-2023-3160 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or... |
| CVE-2023-40303 | HIGH | 7.8 | 0.4% | Aug 14, 2023 | GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions ... |
| CVE-2023-3267 | HIGH | 8.8 | 1.7% | Aug 14, 2023 | When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. T... |
| CVE-2023-3263 | HIGH | 7.5 | 0.6% | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the ... |
| CVE-2023-40296 | HIGH | 7.5 | 0.7% | Aug 14, 2023 | async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when proce... |
| CVE-2023-40295 | HIGH | 8.8 | 0.7% | Aug 14, 2023 | libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c. |
| CVE-2023-3261 | HIGH | 7.2 | 0.7% | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in th... |
| CVE-2023-3260 | HIGH | 8.8 | 1.2% | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `us... |
| CVE-2023-40283 | HIGH | 7.8 | 0.6% | Aug 14, 2023 | An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is ... |
| CVE-2023-40274 | HIGH | 7.5 | 0.9% | Aug 14, 2023 | An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zol... |
| CVE-2023-39406 | HIGH | 7.5 | 0.4% | Aug 13, 2023 | Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps ... |
| CVE-2023-39404 | HIGH | 7.5 | 0.4% | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation o... |
| CVE-2023-39397 | HIGH | 7.5 | 0.4% | Aug 13, 2023 | Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability ma... |
| CVE-2023-39395 | HIGH | 7.5 | 0.4% | Aug 13, 2023 | Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnera... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now