2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41064HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1...
CVE-2023-41061HIGH7.8A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1...
CVE-2023-40060HIGH7.2A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass m...
CVE-2023-30800HIGH7.5The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthent...
CVE-2023-40942CRITICAL9.8Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/Set...
CVE-2023-39711MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-3747MEDIUM5.5Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes ca...
CVE-2023-39424HIGH8.8A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to u...
CVE-2023-39423CRITICAL9.1The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using ...
CVE-2023-39422CRITICAL9.8The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. ...
CVE-2023-39421HIGH7.7The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for thir...
CVE-2023-39420HIGH8.8The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customer...
CVE-2023-36635MEDIUM4.3An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r...
CVE-2023-39240HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is c...
CVE-2023-39239HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused...
CVE-2023-39238HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation ...
CVE-2023-4815HIGH8.8Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
CVE-2023-39237HIGH8.8 ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attac...
CVE-2023-39236HIGH8.8 ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker ...
CVE-2023-38033HIGH8.8 ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remo...
CVE-2023-38032HIGH8.8 ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacke...
CVE-2023-38031HIGH8.8 ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker wi...
CVE-2023-34357HIGH7.8 Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent o...
CVE-2023-4792MEDIUM4.3The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplica...
CVE-2023-4772MEDIUM5.4The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now