2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6351 | HIGH | 8.8 | 0.9% | Nov 29, 2023 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6350 | HIGH | 8.8 | 1.1% | Nov 29, 2023 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6348 | HIGH | 8.8 | 1.0% | Nov 29, 2023 | Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the ... |
| CVE-2023-6347 | HIGH | 8.8 | 1.1% | Nov 29, 2023 | Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap co... |
| CVE-2023-6346 | HIGH | 8.8 | 1.0% | Nov 29, 2023 | Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit hea... |
| CVE-2023-6345 | CRITICAL | 9.6 | 19.6% | Nov 29, 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the rend... |
| CVE-2023-6070 | MEDIUM | 4.3 | 0.2% | Nov 29, 2023 | A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user t... |
| CVE-2023-45484 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter... |
| CVE-2023-45483 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in th... |
| CVE-2023-45482 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in th... |
| CVE-2023-45481 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter... |
| CVE-2023-45480 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the... |
| CVE-2023-45479 | CRITICAL | 9.8 | 1.0% | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in th... |
| CVE-2023-47462 | CRITICAL | 9.8 | 1.3% | Nov 29, 2023 | Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary co... |
| CVE-2023-46887 | HIGH | 7.5 | 0.3% | Nov 29, 2023 | In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability. |
| CVE-2023-46886 | CRITICAL | 9.1 | 1.0% | Nov 29, 2023 | Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary m... |
| CVE-2023-24294 | HIGH | 7.5 | 0.9% | Nov 29, 2023 | Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component Netlin... |
| CVE-2023-23325 | CRITICAL | 9.8 | 2.0% | Nov 29, 2023 | Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the Ne... |
| CVE-2023-23324 | CRITICAL | 9.8 | 0.9% | Nov 29, 2023 | Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator ... |
| CVE-2023-46944 | HIGH | 7.8 | 1.2% | Nov 28, 2023 | An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis... |
| CVE-2023-49092 | MEDIUM | 5.9 | 0.6% | Nov 28, 2023 | RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information abo... |
| CVE-2023-48193 | CRITICAL | 9.8 | 2.0% | Nov 28, 2023 | Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via by... |
| CVE-2023-29066 | LOW | 3.5 | 0.3% | Nov 28, 2023 | The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini... |
| CVE-2023-29065 | MEDIUM | 4.3 | 0.3% | Nov 28, 2023 | The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat ... |
| CVE-2023-29064 | MEDIUM | 4.3 | 0.3% | Nov 28, 2023 | The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now