2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44470HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.
CVE-2023-44241HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions.
CVE-2023-30801CRITICAL9.8All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The...
CVE-2023-5450HIGH7.8 An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an at...
CVE-2023-45226HIGH7.4 The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credent...
CVE-2023-45219MEDIUM4.4 Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allo...
CVE-2023-43788MEDIUM5.5A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This ...
CVE-2023-43787HIGH7.8A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a lo...
CVE-2023-43786MEDIUM5.5A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local ...
CVE-2023-43785MEDIUM5.5A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows ...
CVE-2023-43746HIGH8.7 When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance m...
CVE-2023-43611HIGH7.8 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati...
CVE-2023-43485MEDIUM5.5 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audi...
CVE-2023-42768HIGH7.2 When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's rol...
CVE-2023-41964MEDIUM6.5 The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Sof...
CVE-2023-41373CRITICAL9.9 A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker...
CVE-2023-41253MEDIUM5.5 When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintex...
CVE-2023-41085HIGH7.5 When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Note: Software versions...
CVE-2023-40542HIGH7.5When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can ca...
CVE-2023-40537HIGH8.1 An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configurat...
CVE-2023-40534HIGH7.5When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using th...
CVE-2023-39447MEDIUM4.4 When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log....
CVE-2023-44763MEDIUM5.4Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cros...
CVE-2023-45601HIGH7.8A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1...
CVE-2023-45205HIGH7.8A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is instal...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now