2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-36623HIGH7.8The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC addre...
CVE-2023-36622HIGH7.2The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated admin...
CVE-2023-34457HIGH7.5MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to vers...
CVE-2023-35001HIGH7.8Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP...
CVE-2023-34473HIGH8.8 AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful ...
CVE-2023-34471HIGH8.1 AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-b...
CVE-2023-34337HIGH8.8 AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based mess...
CVE-2023-31248HIGH7.8Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check...
CVE-2023-30607HIGH8.8icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, t...
CVE-2023-36933HIGH7.5In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023....
CVE-2023-36932HIGH8.1In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1....
CVE-2023-31194HIGH7.8An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A sp...
CVE-2023-27390HIGH7.8A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A speciall...
CVE-2023-35979HIGH7.5There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management in...
CVE-2023-35975HIGH8.1An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t...
CVE-2023-35974HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2023-35973HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2023-35972HIGH7.2An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful...
CVE-2023-3089HIGH7.5A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was ...
CVE-2023-37212HIGH8.8Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-37211HIGH8.8Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidenc...
CVE-2023-37209HIGH8.8A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and ...
CVE-2023-37203HIGH7.8Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to...
CVE-2023-2880HIGH7.5Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal v...
CVE-2023-37208HIGH7.8When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerabilit...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now