2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-21152MEDIUM5.5In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a m...
CVE-2023-21151MEDIUM6.7In the Google BMS kernel module, there is a possible out of bounds write due to a heap buffer overflow. This could lead ...
CVE-2023-21150MEDIUM4.4In handle_set_parameters_ctrl of hal_socket.c, there is a possible out of bounds read due to an incorrect bounds check. ...
CVE-2023-21148MEDIUM4.4In BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing null check. This co...
CVE-2023-21146MEDIUM6.7there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with...
CVE-2023-20199MEDIUM6.6A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypa...
CVE-2023-20188MEDIUM4.8A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus...
CVE-2023-20136MEDIUM6.5A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privilege...
CVE-2023-20120MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ...
CVE-2023-20119MEDIUM6.1A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, ...
CVE-2023-20116MEDIUM5.7A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and...
CVE-2023-20105MEDIUM6.5A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communicati...
CVE-2023-20028MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ...
CVE-2023-3445MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.
CVE-2023-30259MEDIUM5.5A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information v...
CVE-2023-3034MEDIUM6.1Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
CVE-2023-3407MEDIUM4.3The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40....
CVE-2023-1844MEDIUM4.3The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capabil...
CVE-2023-3427MEDIUM4.3The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2023-3332MEDIUM4.8Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26...
CVE-2023-3331MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26...
CVE-2023-3330MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, ...
CVE-2023-36464MEDIUM5.5pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an inf...
CVE-2023-36463MEDIUM6.1Meldekarten generator is an open source project to create a program, running locally in the browser without the need for...
CVE-2023-23468MEDIUM5.5IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insuffic...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now