2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37117 | CRITICAL | 9.8 | 0.9% | Jan 12, 2024 | A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP. |
| CVE-2023-34061 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated att... |
| CVE-2023-6040 | HIGH | 7.8 | 0.3% | Jan 12, 2024 | An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables:... |
| CVE-2023-52339 | MEDIUM | 6.5 | 1.1% | Jan 12, 2024 | In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in bu... |
| CVE-2023-40250 | HIGH | 8.8 | 0.6% | Jan 12, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows O... |
| CVE-2023-36842 | MEDIUM | 6.5 | 0.3% | Jan 12, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networ... |
| CVE-2023-51350 | CRITICAL | 9.8 | 1.3% | Jan 11, 2024 | A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code v... |
| CVE-2023-46474 | HIGH | 7.2 | 23.4% | Jan 11, 2024 | File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a c... |
| CVE-2023-7226 | MEDIUM | 6.5 | 0.4% | Jan 11, 2024 | A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknow... |
| CVE-2023-50129 | MEDIUM | 6.5 | 0.1% | Jan 11, 2024 | Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief ... |
| CVE-2023-50128 | MEDIUM | 5.3 | 0.2% | Jan 11, 2024 | The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for ... |
| CVE-2023-50127 | MEDIUM | 5.9 | 0.4% | Jan 11, 2024 | Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionalit... |
| CVE-2023-50126 | MEDIUM | 6.5 | 0.1% | Jan 11, 2024 | Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned ta... |
| CVE-2023-50125 | MEDIUM | 5.9 | 0.4% | Jan 11, 2024 | A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm sys... |
| CVE-2023-50124 | MEDIUM | 6.8 | 0.4% | Jan 11, 2024 | Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface... |
| CVE-2023-50123 | HIGH | 8.1 | 0.6% | Jan 11, 2024 | The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This co... |
| CVE-2023-51782 | HIGH | 7 | 0.3% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because ... |
| CVE-2023-51781 | HIGH | 7 | 0.3% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free becaus... |
| CVE-2023-51780 | HIGH | 7 | 0.5% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because o... |
| CVE-2023-50671 | HIGH | 7.8 | 0.4% | Jan 11, 2024 | In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write ... |
| CVE-2023-6554 | MEDIUM | 6.5 | 0.6% | Jan 11, 2024 | When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it ... |
| CVE-2023-5118 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnota... |
| CVE-2023-51989 | — | — | — | Jan 11, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-51987. Reason: This candidate is a reservation d... |
| CVE-2023-51987 | CRITICAL | 9.8 | 0.9% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator... |
| CVE-2023-51984 | CRITICAL | 9.8 | 2.0% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attack... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now