2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-0971HIGH8.8A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration...
CVE-2023-2911HIGH7.5If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `st...
CVE-2023-2829HIGH7.5A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validat...
CVE-2023-2828HIGH7.5Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the...
CVE-2023-0026HIGH7.5An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O...
CVE-2023-27243HIGH7.5An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a...
CVE-2023-34981HIGH7.5A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response di...
CVE-2023-3339HIGH7.5A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected b...
CVE-2023-35166HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2023-32274HIGH7.5 Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android applica...
CVE-2023-2533HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific condition...
CVE-2023-1999HIGH7.5There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop ...
CVE-2023-1862HIGH7.3Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe b...
CVE-2023-26436HIGH8.8Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not proper...
CVE-2023-3320HIGH8.8The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,...
CVE-2023-3312HIGH7.5A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, duri...
CVE-2023-35843HIGH7.5NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access...
CVE-2023-34166HIGH7.5Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerabi...
CVE-2023-34163HIGH7.5Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause...
CVE-2023-34162HIGH7.5Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may ...
CVE-2023-34161HIGH7.5nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability ma...
CVE-2023-34155HIGH7.5Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this vulnerability may aff...
CVE-2023-31410HIGH7.4A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo...
CVE-2023-34373HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.
CVE-2023-2805HIGH7.2The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now