2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-23907HIGH7.5A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-cra...
CVE-2023-23571HIGH7.5An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafte...
CVE-2023-23550HIGH7.2An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5...
CVE-2023-23546HIGH8.1A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-craf...
CVE-2023-22659HIGH7.2An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0...
CVE-2023-22653HIGH8.8An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0...
CVE-2023-22371HIGH8.1An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2...
CVE-2023-22365HIGH7.2An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32...
CVE-2023-22306HIGH7.2An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5....
CVE-2023-22299HIGH8.8An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. ...
CVE-2023-36968HIGH7.2A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by ...
CVE-2023-36189HIGH7.5SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via th...
CVE-2023-35937HIGH8.8Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere...
CVE-2023-37241HIGH7.5Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to r...
CVE-2023-37239HIGH7.5Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit thi...
CVE-2023-34164HIGH7.5Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation ...
CVE-2023-1695HIGH7.5Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab...
CVE-2023-1691HIGH7.5Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab...
CVE-2023-3523HIGH7.1Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
CVE-2023-30670HIGH7.8Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacke...
CVE-2023-30669HIGH7.8Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local atta...
CVE-2023-30668HIGH7.8Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker...
CVE-2023-30666HIGH7.8Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows lo...
CVE-2023-30664HIGH7.8Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to la...
CVE-2023-30663HIGH7.8Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now