2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41064 | HIGH | 7.8 | 15.3% | Sep 7, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1... |
| CVE-2023-41061 | HIGH | 7.8 | 3.2% | Sep 7, 2023 | A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1... |
| CVE-2023-40060 | HIGH | 7.2 | 0.9% | Sep 7, 2023 | A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass m... |
| CVE-2023-30800 | HIGH | 7.5 | 1.7% | Sep 7, 2023 | The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthent... |
| CVE-2023-40942 | CRITICAL | 9.8 | 0.7% | Sep 7, 2023 | Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/Set... |
| CVE-2023-39711 | MEDIUM | 6.1 | 0.5% | Sep 7, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta... |
| CVE-2023-3747 | MEDIUM | 5.5 | 0.2% | Sep 7, 2023 | Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes ca... |
| CVE-2023-39424 | HIGH | 8.8 | 0.7% | Sep 7, 2023 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to u... |
| CVE-2023-39423 | CRITICAL | 9.1 | 0.5% | Sep 7, 2023 | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using ... |
| CVE-2023-39422 | CRITICAL | 9.8 | 0.4% | Sep 7, 2023 | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. ... |
| CVE-2023-39421 | HIGH | 7.7 | 0.4% | Sep 7, 2023 | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for thir... |
| CVE-2023-39420 | HIGH | 8.8 | 0.5% | Sep 7, 2023 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customer... |
| CVE-2023-36635 | MEDIUM | 4.3 | 0.4% | Sep 7, 2023 | An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r... |
| CVE-2023-39240 | HIGH | 7.2 | 1.2% | Sep 7, 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is c... |
| CVE-2023-39239 | HIGH | 7.2 | 1.2% | Sep 7, 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused... |
| CVE-2023-39238 | HIGH | 7.2 | 1.2% | Sep 7, 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation ... |
| CVE-2023-4815 | HIGH | 8.8 | 0.7% | Sep 7, 2023 | Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3. |
| CVE-2023-39237 | HIGH | 8.8 | 1.1% | Sep 7, 2023 | ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attac... |
| CVE-2023-39236 | HIGH | 8.8 | 1.1% | Sep 7, 2023 | ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker ... |
| CVE-2023-38033 | HIGH | 8.8 | 1.1% | Sep 7, 2023 | ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remo... |
| CVE-2023-38032 | HIGH | 8.8 | 1.1% | Sep 7, 2023 | ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacke... |
| CVE-2023-38031 | HIGH | 8.8 | 1.1% | Sep 7, 2023 | ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker wi... |
| CVE-2023-34357 | HIGH | 7.8 | 0.2% | Sep 7, 2023 | Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent o... |
| CVE-2023-4792 | MEDIUM | 4.3 | 0.4% | Sep 7, 2023 | The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplica... |
| CVE-2023-4772 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now