2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6351HIGH8.8Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap...
CVE-2023-6350HIGH8.8Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap...
CVE-2023-6348HIGH8.8Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the ...
CVE-2023-6347HIGH8.8Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap co...
CVE-2023-6346HIGH8.8Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit hea...
CVE-2023-6345CRITICAL9.6Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the rend...
CVE-2023-6070MEDIUM4.3 A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user t...
CVE-2023-45484CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter...
CVE-2023-45483CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in th...
CVE-2023-45482CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in th...
CVE-2023-45481CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter...
CVE-2023-45480CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the...
CVE-2023-45479CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in th...
CVE-2023-47462CRITICAL9.8Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary co...
CVE-2023-46887HIGH7.5In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
CVE-2023-46886CRITICAL9.1Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary m...
CVE-2023-24294HIGH7.5Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component Netlin...
CVE-2023-23325CRITICAL9.8Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the Ne...
CVE-2023-23324CRITICAL9.8Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator ...
CVE-2023-46944HIGH7.8An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis...
CVE-2023-49092MEDIUM5.9RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information abo...
CVE-2023-48193CRITICAL9.8Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via by...
CVE-2023-29066LOW3.5The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini...
CVE-2023-29065MEDIUM4.3The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat ...
CVE-2023-29064MEDIUM4.3The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now