2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40830CRITICAL9.8Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
CVE-2023-43976HIGH8.1An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race conditio...
CVE-2023-5255HIGH7.5For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates fro...
CVE-2023-4911HIGH7.8A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environ...
CVE-2023-4732MEDIUM4.7A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker...
CVE-2023-34970MEDIUM4.7A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bou...
CVE-2023-33200MEDIUM4.7A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the sys...
CVE-2023-4817HIGH8.8This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the uploa...
CVE-2023-4564MEDIUM4.8This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter wi...
CVE-2023-3196MEDIUM4.8This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page de...
CVE-2023-2222Rejected reason: This was deemed not a security vulnerability by upstream.
CVE-2023-4886MEDIUM4.4A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain...
CVE-2023-4885MEDIUM5.9Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communication...
CVE-2023-4884HIGH7.5An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to t...
CVE-2023-4883HIGH7.5 Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the corr...
CVE-2023-4882HIGH7.5DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could...
CVE-2023-4929HIGH8.8All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. ...
CVE-2023-41693HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions.
CVE-2023-41244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <= 1.0.9 versions.
CVE-2023-40558HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3....
CVE-2023-3350HIGH7.5A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the...
CVE-2023-3349HIGH7.5Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to ret...
CVE-2023-39158MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 version...
CVE-2023-32091HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <= 0.9.4 versions.
CVE-2023-2544MEDIUM6.5Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now