2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-3208HIGH8.8A vulnerability, which was classified as critical, has been found in RoadFlow Visual Process Engine .NET Core Mvc 2.13.3...
CVE-2023-3206HIGH7.5A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown ...
CVE-2023-34494HIGH7.5NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
CVE-2023-34488HIGH7.8NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes...
CVE-2023-33290HIGH7.5The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to ...
CVE-2023-33253HIGH8.8LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an exe...
CVE-2023-35035HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-35033HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-35032HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and ...
CVE-2023-35031HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-25911HIGH8.8The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web ap...
CVE-2023-22586HIGH7.5The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.
CVE-2023-22584HIGH7.5The Danfoss AK-EM100 stores login credentials in cleartext.
CVE-2023-26132HIGH7.5Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the se...
CVE-2023-3141HIGH7.1A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This...
CVE-2023-29766HIGH7.8An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the datab...
CVE-2023-29757HIGH7.8An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attack...
CVE-2023-29755HIGH7.8An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manip...
CVE-2023-29752HIGH7.8An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privileg...
CVE-2023-29749HIGH7.8An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks ...
CVE-2023-2454HIGH7.2schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could perm...
CVE-2023-27706HIGH7.1Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, ac...
CVE-2023-33557HIGH8.8Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
CVE-2023-30262HIGH8.8An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a r...
CVE-2023-32731HIGH7.5When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now