2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-22247HIGH7.5Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability...
CVE-2023-1380HIGH7.1A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cf...
CVE-2023-1078HIGH7.8A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses li...
CVE-2023-1077HIGH7In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as th...
CVE-2023-0494HIGH7.8A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be ex...
CVE-2023-25818HIGH7.1Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to re...
CVE-2023-25828HIGH7.2 Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albu...
CVE-2023-1654HIGH7.8Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
CVE-2023-0955HIGH8.8The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to per...
CVE-2023-0441HIGH8.1The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenti...
CVE-2023-27296HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by a...
CVE-2023-1655HIGH7.8Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
CVE-2023-1145HIGH7.8 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerabilit...
CVE-2023-1144HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in ...
CVE-2023-1143HIGH8.8In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could al...
CVE-2023-1141HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could ...
CVE-2023-1139HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targe...
CVE-2023-1138HIGH7.5Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, whi...
CVE-2023-1137HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user cou...
CVE-2023-1136HIGH7.5In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a vali...
CVE-2023-1135HIGH7.8 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set in...
CVE-2023-1134HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which...
CVE-2023-24094HIGH7.5An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via c...
CVE-2023-25017HIGH8.1RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user pri...
CVE-2023-24841HIGH7.2HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An au...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now