2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-27875HIGH7.5IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Fo...
CVE-2023-1433HIGH7.2A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problemat...
CVE-2023-24671HIGH7.8VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to exe...
CVE-2023-24760HIGH8.8An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserContr...
CVE-2023-25281HIGH7.5A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a d...
CVE-2023-28466HIGH7do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race cond...
CVE-2023-28460HIGH7.2A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted pa...
CVE-2023-28338HIGH7.5Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboun...
CVE-2023-28337HIGH8.8When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be p...
CVE-2023-28099HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_l...
CVE-2023-28098HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially cr...
CVE-2023-28097HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SI...
CVE-2023-1389HIGH8.8TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i...
CVE-2023-28096HIGH7.5OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and pr...
CVE-2023-28095HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potentia...
CVE-2023-27601HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash...
CVE-2023-27600HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash...
CVE-2023-25267HIGH8.8An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in ...
CVE-2023-28450HIGH7.5An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be...
CVE-2023-27599HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the funct...
CVE-2023-27598HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malf...
CVE-2023-27597HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, when a special...
CVE-2023-27596HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crash...
CVE-2023-26484HIGH8.2KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has ta...
CVE-2023-25345HIGH7.5Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary f...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now