2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3329MEDIUM6.5SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative ...
CVE-2023-39114MEDIUM5.5ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibS...
CVE-2023-39113MEDIUM5.5ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulne...
CVE-2023-3978MEDIUM6.1Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be....
CVE-2023-36081MEDIUM5.4Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to exe...
CVE-2023-29409MEDIUM5.3Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signat...
CVE-2023-29408MEDIUM6.5The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit thi...
CVE-2023-29407MEDIUM6.5A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very...
CVE-2023-3470MEDIUM6.1 Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ac...
CVE-2023-38423MEDIUM5.4 A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allow...
CVE-2023-38419MEDIUM4.3An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending un...
CVE-2023-38138MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ...
CVE-2023-36858MEDIUM5.5 An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an...
CVE-2023-36494MEDIUM4.4 Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of ...
CVE-2023-38330MEDIUM5.3OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administrat...
CVE-2023-23476MEDIUM6.5IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic...
CVE-2023-33383MEDIUM5.3Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t...
CVE-2023-33257MEDIUM5.4Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
CVE-2023-26316MEDIUM6.1A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whi...
CVE-2023-26450MEDIUM5.4The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious scrip...
CVE-2023-26449MEDIUM5.4The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script...
CVE-2023-26448MEDIUM5.4Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handler...
CVE-2023-26447MEDIUM5.4The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controlla...
CVE-2023-26446MEDIUM5.4The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script c...
CVE-2023-26445MEDIUM5.4Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets proce...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now