2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21740 | HIGH | 7.8 | 1.1% | Dec 12, 2023 | Windows Media Remote Code Execution Vulnerability |
| CVE-2023-20275 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepowe... |
| CVE-2023-4421 | MEDIUM | 6.5 | 0.6% | Dec 12, 2023 | The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both ... |
| CVE-2023-48227 | MEDIUM | 4.3 | 0.4% | Dec 12, 2023 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, ... |
| CVE-2023-38694 | MEDIUM | 5.4 | 0.4% | Dec 12, 2023 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, ... |
| CVE-2023-31048 | MEDIUM | 5.3 | 0.8% | Dec 12, 2023 | The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may... |
| CVE-2023-28604 | MEDIUM | 6.1 | 0.5% | Dec 12, 2023 | The fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 allows XSS via a component argument paramet... |
| CVE-2023-28465 | HIGH | 7.5 | 1.3% | Dec 12, 2023 | The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy ar... |
| CVE-2023-26920 | MEDIUM | 6.5 | 1.2% | Dec 12, 2023 | fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution. |
| CVE-2023-6593 | CRITICAL | 9.8 | 0.7% | Dec 12, 2023 | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker t... |
| CVE-2023-50495 | MEDIUM | 6.5 | 1.0% | Dec 12, 2023 | NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry(). |
| CVE-2023-46456 | CRITICAL | 9.8 | 24.7% | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN c... |
| CVE-2023-46455 | HIGH | 7.5 | 47.0% | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attac... |
| CVE-2023-46454 | CRITICAL | 9.8 | 23.5% | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted p... |
| CVE-2023-6193 | MEDIUM | 5.3 | 0.8% | Dec 12, 2023 | quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which ... |
| CVE-2023-49994 | MEDIUM | 5.5 | 0.4% | Dec 12, 2023 | Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c. |
| CVE-2023-49993 | MEDIUM | 5.3 | 0.4% | Dec 12, 2023 | Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c. |
| CVE-2023-49992 | MEDIUM | 5.3 | 0.4% | Dec 12, 2023 | Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c. |
| CVE-2023-49991 | MEDIUM | 5.3 | 0.4% | Dec 12, 2023 | Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c... |
| CVE-2023-49990 | MEDIUM | 5.3 | 0.4% | Dec 12, 2023 | Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c. |
| CVE-2023-49692 | MEDIUM | 6.7 | 0.6% | Dec 12, 2023 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDC... |
| CVE-2023-49691 | MEDIUM | 6.7 | 0.6% | Dec 12, 2023 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM... |
| CVE-2023-48431 | HIGH | 8.6 | 0.6% | Dec 12, 2023 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctl... |
| CVE-2023-48430 | LOW | 2.7 | 0.6% | Dec 12, 2023 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices do... |
| CVE-2023-48429 | LOW | 2.7 | 0.6% | Dec 12, 2023 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now