2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43495MEDIUM5.4Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of '...
CVE-2023-43494MEDIUM4.3Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive buil...
CVE-2023-42660HIGH8.8 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...
CVE-2023-42656MEDIUM6.1 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...
CVE-2023-40043HIGH7.2 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...
CVE-2023-5074CRITICAL9.8Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Li...
CVE-2023-2508MEDIUM6.5The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attac...
CVE-2023-2262CRITICAL9.8 A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited...
CVE-2023-43636HIGH8.8 In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in t...
CVE-2023-43635HIGH8.8 Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism...
CVE-2023-43630HIGH8.8PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit ...
CVE-2023-42464CRITICAL9.8A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When pa...
CVE-2023-43478CRITICAL9.8fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated...
CVE-2023-43207CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upl...
CVE-2023-43206CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_d...
CVE-2023-43204CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50....
CVE-2023-43203CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.
CVE-2023-43202CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_downl...
CVE-2023-43201CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ex...
CVE-2023-43200CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data...
CVE-2023-43199CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/logi...
CVE-2023-43198CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/h...
CVE-2023-43197CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.as...
CVE-2023-43196CRITICAL9.8D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp f...
CVE-2023-41902HIGH7.8An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to esc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now