2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20033HIGH8.6A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauth...
CVE-2023-4129HIGH7.5 Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticate...
CVE-2023-43125HIGH8.2 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Te...
CVE-2023-43124HIGH7.1 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Te...
CVE-2023-32458HIGH7.8 Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerab...
CVE-2023-5223CRITICAL9.9A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects s...
CVE-2023-5222CRITICAL9.8A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the...
CVE-2023-5221CRITICAL9.8A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/ind...
CVE-2023-5197MEDIUM6.6A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-5192MEDIUM6.5Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.
CVE-2023-5183HIGH8.8Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Aut...
CVE-2023-5176CRITICAL9.8Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence ...
CVE-2023-5175CRITICAL9.8During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed fr...
CVE-2023-5174CRITICAL9.8If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer...
CVE-2023-5173HIGH7.5In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly u...
CVE-2023-5172CRITICAL9.8A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential...
CVE-2023-5171MEDIUM6.5During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to ...
CVE-2023-5170HIGH7.4In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memo...
CVE-2023-5169MEDIUM6.5A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds writ...
CVE-2023-5168CRITICAL9.8A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write...
CVE-2023-5162MEDIUM5.4The Options for Twenty Seventeen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social-links' sh...
CVE-2023-5161MEDIUM5.4The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and...
CVE-2023-5157HIGH7.5A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to ca...
CVE-2023-5135MEDIUM5.4The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-tu...
CVE-2023-4934HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now