2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41107MEDIUM5.4TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.
CVE-2023-41012CRITICAL9.8An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to exe...
CVE-2023-36361CRITICAL9.8Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
CVE-2023-4480MEDIUM5.5 Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker...
CVE-2023-40743CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that lo...
CVE-2023-32086Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-2453HIGH8.8There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently...
CVE-2023-20898HIGH7.8Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters pr...
CVE-2023-20897MEDIUM5.3Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the reques...
CVE-2023-38569MEDIUM5.4Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execut...
CVE-2023-36492MEDIUM6.1Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to e...
CVE-2023-40705MEDIUM5.4Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authentica...
CVE-2023-40535MEDIUM5.4Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authentic...
CVE-2023-39938MEDIUM6.1Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to...
CVE-2023-39448HIGH8.8Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create ar...
CVE-2023-38574MEDIUM6.1Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users t...
CVE-2023-4540HIGH7.5Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation an...
CVE-2023-41910CRITICAL9.8An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a mal...
CVE-2023-41909HIGH7.5An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed...
CVE-2023-41908MEDIUM5.3Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
CVE-2023-33021HIGH7.8Memory corruption in Graphics while processing user packets for command submission.
CVE-2023-33020HIGH7.5Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
CVE-2023-33019HIGH7.5Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel...
CVE-2023-33016HIGH7.5Transient DOS in WLAN firmware while parsing MLO (multi-link operation).
CVE-2023-33015HIGH7.5Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now