2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39663HIGH7.5Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJ...
CVE-2023-39268CRITICAL9.8A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving spe...
CVE-2023-39267MEDIUM6.5An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful ...
CVE-2023-39266MEDIUM6.1A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct...
CVE-2023-3252MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges coul...
CVE-2023-3251MEDIUM4.9 A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover st...
CVE-2023-39522MEDIUM5.3goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage...
CVE-2023-34039CRITICAL9.8Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g...
CVE-2023-20890HIGH7.2Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with admin...
CVE-2023-41037MEDIUM4.3OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Message...
CVE-2023-40890CRITICAL9.8A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR...
CVE-2023-40889CRITICAL9.8A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes ...
CVE-2023-3646HIGH7.5On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error ma...
CVE-2023-39616HIGH7.5AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p...
CVE-2023-39615MEDIUM6.5Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxm...
CVE-2023-24548MEDIUM6.5On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tun...
CVE-2023-41376HIGH7.5Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enab...
CVE-2023-41362HIGH7.2MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use ...
CVE-2023-38802HIGH7.5FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a craft...
CVE-2023-38283MEDIUM5.3In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant r...
CVE-2023-0654LOW3.7Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the ev...
CVE-2023-0238MEDIUM5.5Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic...
CVE-2023-40787CRITICAL9.8In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks,...
CVE-2023-23774HIGH8.4Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller expos...
CVE-2023-23773HIGH8.8Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic sig...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now