2023 CVE Vulnerabilities

31,402 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26319HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Route...
CVE-2023-26318HIGH7.2Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Over...
CVE-2023-5511HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
CVE-2023-45194MEDIUM4.3Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-...
CVE-2023-44689MEDIUM4.3e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versio...
CVE-2023-26220MEDIUM5.4The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploita...
CVE-2023-36127HIGH7.5User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where ...
CVE-2023-36126MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Sc...
CVE-2023-45312HIGH8.8In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access...
CVE-2023-45648MEDIUM5.3Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 throug...
CVE-2023-31096HIGH7.8An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There ...
CVE-2023-5497HIGH8.8A vulnerability classified as critical has been found in Tongda OA 2017 11.10. Affected is an unknown function of the fi...
CVE-2023-4309CRITICAL9.8Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. T...
CVE-2023-45129MEDIUM4.9Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0...
CVE-2023-42795MEDIUM5.3Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M...
CVE-2023-42794MEDIUM5.9Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat ...
CVE-2023-41774HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41773HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41772HIGH7.8Win32k Elevation of Privilege Vulnerability
CVE-2023-41771HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41770HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41769HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41768HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41767HIGH8.1Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41766HIGH7.8Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now