2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35957HIGH7.8Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT...
CVE-2023-35956HIGH7.8Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT...
CVE-2023-35955HIGH7.8Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT...
CVE-2023-35704HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A ...
CVE-2023-35703HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A ...
CVE-2023-35702HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A ...
CVE-2023-35128HIGH7.8An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3...
CVE-2023-35057HIGH7.8An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3....
CVE-2023-35004HIGH7.8An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A spe...
CVE-2023-34436HIGH7.8An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A speci...
CVE-2023-34087HIGH7.8An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A ...
CVE-2023-32650HIGH7.8An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when com...
CVE-2023-7224HIGH7.8OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries ...
CVE-2023-51701HIGH7.5fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server bui...
CVE-2023-6552MEDIUM6.1Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerabil...
CVE-2023-6921CRITICAL9.1Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modi...
CVE-2023-5091MEDIUM5.5Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GP...
CVE-2023-41710MEDIUM5.4User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when addin...
CVE-2023-29052MEDIUM5.4Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitiz...
CVE-2023-29051HIGH8.1User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing s...
CVE-2023-29050CRITICAL9.6The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac...
CVE-2023-29049MEDIUM6.1The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure us...
CVE-2023-29048HIGH8.8A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as th...
CVE-2023-47140HIGH8.1IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.
CVE-2023-7215MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affect...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now