2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50628 | CRITICAL | 9.8 | 1.2% | Dec 20, 2023 | Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive ... |
| CVE-2023-50044 | CRITICAL | 9.8 | 0.9% | Dec 20, 2023 | Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an i... |
| CVE-2023-6975 | CRITICAL | 9.8 | 2.0% | Dec 20, 2023 | A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models... |
| CVE-2023-6974 | CRITICAL | 9.8 | 1.5% | Dec 20, 2023 | A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it cou... |
| CVE-2023-47702 | CRITICAL | 9.1 | 1.0% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An ... |
| CVE-2023-27172 | CRITICAL | 9.1 | 0.7% | Dec 20, 2023 | Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the ... |
| CVE-2023-45887 | CRITICAL | 9.8 | 1.6% | Dec 20, 2023 | DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code ... |
| CVE-2023-6930 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulner... |
| CVE-2023-6929 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the ... |
| CVE-2023-6928 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in... |
| CVE-2023-49004 | CRITICAL | 9.8 | 1.9% | Dec 19, 2023 | An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to t... |
| CVE-2023-47267 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and W... |
| CVE-2023-49750 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Coupon... |
| CVE-2023-48738 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto ... |
| CVE-2023-34027 | CRITICAL | 9.8 | 0.8% | Dec 19, 2023 | Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Vi... |
| CVE-2023-50272 | CRITICAL | 9.8 | 0.6% | Dec 19, 2023 | A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out ... |
| CVE-2023-46266 | CRITICAL | 9.1 | 3.5% | Dec 19, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2023-46265 | CRITICAL | 9.8 | 4.0% | Dec 19, 2023 | An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Requ... |
| CVE-2023-46264 | CRITICAL | 9.8 | 90.2% | Dec 19, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could... |
| CVE-2023-46263 | CRITICAL | 9.8 | 81.9% | Dec 19, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could... |
| CVE-2023-46261 | CRITICAL | 9.8 | 11.3% | Dec 19, 2023 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r... |
| CVE-2023-46260 | CRITICAL | 9.8 | 9.8% | Dec 19, 2023 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r... |
| CVE-2023-46259 | CRITICAL | 9.8 | 11.3% | Dec 19, 2023 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r... |
| CVE-2023-46258 | CRITICAL | 9.8 | 6.8% | Dec 19, 2023 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r... |
| CVE-2023-46257 | CRITICAL | 9.8 | 11.3% | Dec 19, 2023 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now