2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3729 | HIGH | 8.8 | 0.3% | Aug 1, 2023 | Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinc... |
| CVE-2023-3728 | HIGH | 8.8 | 0.7% | Aug 1, 2023 | Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-3727 | HIGH | 8.8 | 0.7% | Aug 1, 2023 | Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-3494 | HIGH | 8.8 | 0.2% | Aug 1, 2023 | The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The in... |
| CVE-2023-3107 | HIGH | 7.5 | 0.5% | Aug 1, 2023 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled pac... |
| CVE-2023-36351 | HIGH | 7.8 | 0.7% | Aug 1, 2023 | An issue in Viatom Health ViHealth for Android v.2.74.58 and before allows a remote attacker to execute arbitrary code v... |
| CVE-2023-33563 | HIGH | 8.8 | 0.6% | Aug 1, 2023 | In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on... |
| CVE-2023-31427 | HIGH | 7.8 | 0.2% | Aug 1, 2023 | Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with kn... |
| CVE-2023-31425 | HIGH | 7.8 | 0.3% | Aug 1, 2023 | A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS... |
| CVE-2023-3718 | HIGH | 8.8 | 1.4% | Aug 1, 2023 | An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation o... |
| CVE-2023-39147 | HIGH | 7.8 | 1.1% | Aug 1, 2023 | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte... |
| CVE-2023-34552 | HIGH | 8.8 | 0.5% | Aug 1, 2023 | In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type fun... |
| CVE-2023-34551 | HIGH | 8 | 0.5% | Aug 1, 2023 | In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server ca... |
| CVE-2023-4055 | HIGH | 7.5 | 0.6% | Aug 1, 2023 | When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no l... |
| CVE-2023-4051 | HIGH | 7.5 | 0.5% | Aug 1, 2023 | A website could have obscured the full screen notification by using the file open dialog. This could have led to user co... |
| CVE-2023-4050 | HIGH | 7.5 | 13.7% | Aug 1, 2023 | In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a pote... |
| CVE-2023-4048 | HIGH | 7.5 | 0.8% | Aug 1, 2023 | An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. ... |
| CVE-2023-4047 | HIGH | 8.8 | 0.6% | Aug 1, 2023 | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting... |
| CVE-2023-39110 | HIGH | 8.8 | 2.7% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPa... |
| CVE-2023-39109 | HIGH | 8.8 | 3.0% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Fun... |
| CVE-2023-39108 | HIGH | 8.8 | 3.0% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Fun... |
| CVE-2023-34634 | HIGH | 7.8 | 7.7% | Aug 1, 2023 | Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green... |
| CVE-2023-26139 | HIGH | 7.5 | 0.7% | Aug 1, 2023 | Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of th... |
| CVE-2023-36984 | HIGH | 7.5 | 0.6% | Aug 1, 2023 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. |
| CVE-2023-36983 | HIGH | 7.5 | 0.6% | Aug 1, 2023 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now