2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4486HIGH7.5Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls ...
CVE-2023-49468HIGH8.8Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at sl...
CVE-2023-49467HIGH8.8Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merg...
CVE-2023-49465HIGH8.8Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_predic...
CVE-2023-49464HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bit...
CVE-2023-49463HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
CVE-2023-49462HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
CVE-2023-49460HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncom...
CVE-2023-6333MEDIUM5.4 The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could all...
CVE-2023-49787Rejected reason: CVE request originates from private repository
CVE-2023-49411CRITICAL9.8Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
CVE-2023-49409CRITICAL9.8Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
CVE-2023-49408CRITICAL9.8Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
CVE-2023-49406CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet...
CVE-2023-49405CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
CVE-2023-49404CRITICAL9.8Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
CVE-2023-48958MEDIUM5.5gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.
CVE-2023-47440MEDIUM6.5Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be inc...
CVE-2023-46871MEDIUM5.3GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:30...
CVE-2023-41905MEDIUM5.4NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated use...
CVE-2023-41172MEDIUM5.4NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).
CVE-2023-41171MEDIUM5.4NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).
CVE-2023-41170MEDIUM6.1NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.
CVE-2023-41169MEDIUM5.4NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).
CVE-2023-41168MEDIUM5.4NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now