2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3329 | MEDIUM | 6.5 | 1.0% | Aug 2, 2023 | SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative ... |
| CVE-2023-39114 | MEDIUM | 5.5 | 0.3% | Aug 2, 2023 | ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibS... |
| CVE-2023-39113 | MEDIUM | 5.5 | 0.3% | Aug 2, 2023 | ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulne... |
| CVE-2023-3978 | MEDIUM | 6.1 | 0.8% | Aug 2, 2023 | Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be.... |
| CVE-2023-36081 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to exe... |
| CVE-2023-29409 | MEDIUM | 5.3 | 1.3% | Aug 2, 2023 | Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signat... |
| CVE-2023-29408 | MEDIUM | 6.5 | 0.9% | Aug 2, 2023 | The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit thi... |
| CVE-2023-29407 | MEDIUM | 6.5 | 0.8% | Aug 2, 2023 | A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very... |
| CVE-2023-3470 | MEDIUM | 6.1 | 0.2% | Aug 2, 2023 | Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ac... |
| CVE-2023-38423 | MEDIUM | 5.4 | 0.3% | Aug 2, 2023 | A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allow... |
| CVE-2023-38419 | MEDIUM | 4.3 | 0.5% | Aug 2, 2023 | An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending un... |
| CVE-2023-38138 | MEDIUM | 6.1 | 0.3% | Aug 2, 2023 | A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ... |
| CVE-2023-36858 | MEDIUM | 5.5 | 0.1% | Aug 2, 2023 | An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an... |
| CVE-2023-36494 | MEDIUM | 4.4 | 0.2% | Aug 2, 2023 | Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of ... |
| CVE-2023-38330 | MEDIUM | 5.3 | 0.4% | Aug 2, 2023 | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administrat... |
| CVE-2023-23476 | MEDIUM | 6.5 | 0.4% | Aug 2, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic... |
| CVE-2023-33383 | MEDIUM | 5.3 | 2.5% | Aug 2, 2023 | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t... |
| CVE-2023-33257 | MEDIUM | 5.4 | 0.3% | Aug 2, 2023 | Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat. |
| CVE-2023-26316 | MEDIUM | 6.1 | 0.3% | Aug 2, 2023 | A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whi... |
| CVE-2023-26450 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious scrip... |
| CVE-2023-26449 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script... |
| CVE-2023-26448 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handler... |
| CVE-2023-26447 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controlla... |
| CVE-2023-26446 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script c... |
| CVE-2023-26445 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets proce... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now