2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-29860HIGH7.5An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensit...
CVE-2023-28065HIGH7.3 Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Wind...
CVE-2023-28073HIGH7.8 Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exp...
CVE-2023-28071HIGH7.1 Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on...
CVE-2023-32463HIGH7.5 Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A r...
CVE-2023-31469HIGH8.8 A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. Th...
CVE-2023-35801HIGH8.1A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation ...
CVE-2023-36193HIGH7.8Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.
CVE-2023-36192HIGH7.8Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture....
CVE-2023-33141HIGH7.5Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
CVE-2023-34241HIGH7.1OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Sta...
CVE-2023-28006HIGH7.8The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
CVE-2023-3114HIGH7.7Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the worksp...
CVE-2023-35133HIGH7.5An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw aff...
CVE-2023-32320HIGH7.5Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are...
CVE-2023-36359HIGH7.5TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflo...
CVE-2023-36358HIGH7.7TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflo...
CVE-2023-36357HIGH7.7An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND...
CVE-2023-36356HIGH7.7TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read ou...
CVE-2023-36354HIGH7.5TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contai...
CVE-2023-2990HIGH7.5Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed messag...
CVE-2023-27083HIGH7.2An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code ...
CVE-2023-36243HIGH7.8FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c.
CVE-2023-36239HIGH8.8libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.
CVE-2023-34923HIGH8.1XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credential...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now