2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44178MEDIUM5.5 A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged att...
CVE-2023-44177MEDIUM5.5 A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low pri...
CVE-2023-44176MEDIUM5.5 A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged att...
CVE-2023-44175HIGH7.5 A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evol...
CVE-2023-41263LOW3.7An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debu...
CVE-2023-41262CRITICAL9.8An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint actio...
CVE-2023-41261MEDIUM5.3An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint actio...
CVE-2023-36843HIGH7.5 An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Jun...
CVE-2023-36841HIGH7.5 An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper ...
CVE-2023-36839MEDIUM6.5 An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of ...
CVE-2023-22392MEDIUM6.5 A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Net...
CVE-2023-27316HIGH7.8SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Serv...
CVE-2023-45511MEDIUM5.5A memory leak in tsMuxer version git-2539d07 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVE-2023-45510HIGH7.5tsMuxer version git-2539d07 was discovered to contain an alloc-dealloc-mismatch (operator new [] vs operator delete) err...
CVE-2023-5562MEDIUM6.1An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When ...
CVE-2023-23632HIGH7.8BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. At...
CVE-2023-43148HIGH8.1SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accou...
CVE-2023-27314HIGH7.5ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability...
CVE-2023-27313HIGH8.8SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a vulnerability which may allow an authenticated unpriv...
CVE-2023-27312MEDIUM4.3SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authe...
CVE-2023-43149HIGH8.8SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user w...
CVE-2023-37637Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-38817. Reason: This record is a reservation duplicate ...
CVE-2023-5072HIGH7.5Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string o...
CVE-2023-45143LOW3.5Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authoriza...
CVE-2023-45142HIGH7.5OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now