2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4486 | HIGH | 7.5 | 0.8% | Dec 7, 2023 | Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls ... |
| CVE-2023-49468 | HIGH | 8.8 | 0.9% | Dec 7, 2023 | Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at sl... |
| CVE-2023-49467 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merg... |
| CVE-2023-49465 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_predic... |
| CVE-2023-49464 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bit... |
| CVE-2023-49463 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc. |
| CVE-2023-49462 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc. |
| CVE-2023-49460 | HIGH | 8.8 | 0.8% | Dec 7, 2023 | libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncom... |
| CVE-2023-6333 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could all... |
| CVE-2023-49787 | — | — | — | Dec 7, 2023 | Rejected reason: CVE request originates from private repository |
| CVE-2023-49411 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. |
| CVE-2023-49409 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet. |
| CVE-2023-49408 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. |
| CVE-2023-49406 | CRITICAL | 9.8 | 1.5% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet... |
| CVE-2023-49405 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. |
| CVE-2023-49404 | CRITICAL | 9.8 | 0.9% | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. |
| CVE-2023-48958 | MEDIUM | 5.5 | 0.3% | Dec 7, 2023 | gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589. |
| CVE-2023-47440 | MEDIUM | 6.5 | 1.0% | Dec 7, 2023 | Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be inc... |
| CVE-2023-46871 | MEDIUM | 5.3 | 0.7% | Dec 7, 2023 | GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:30... |
| CVE-2023-41905 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated use... |
| CVE-2023-41172 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). |
| CVE-2023-41171 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). |
| CVE-2023-41170 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. |
| CVE-2023-41169 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). |
| CVE-2023-41168 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now