2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39663 | HIGH | 7.5 | 0.7% | Aug 29, 2023 | Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJ... |
| CVE-2023-39268 | CRITICAL | 9.8 | 0.7% | Aug 29, 2023 | A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving spe... |
| CVE-2023-39267 | MEDIUM | 6.5 | 0.7% | Aug 29, 2023 | An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful ... |
| CVE-2023-39266 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct... |
| CVE-2023-3252 | MEDIUM | 6.5 | 0.6% | Aug 29, 2023 | An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges coul... |
| CVE-2023-3251 | MEDIUM | 4.9 | 0.5% | Aug 29, 2023 | A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover st... |
| CVE-2023-39522 | MEDIUM | 5.3 | 0.5% | Aug 29, 2023 | goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage... |
| CVE-2023-34039 | CRITICAL | 9.8 | 63.9% | Aug 29, 2023 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g... |
| CVE-2023-20890 | HIGH | 7.2 | 21.6% | Aug 29, 2023 | Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with admin... |
| CVE-2023-41037 | MEDIUM | 4.3 | 0.3% | Aug 29, 2023 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Message... |
| CVE-2023-40890 | CRITICAL | 9.8 | 1.8% | Aug 29, 2023 | A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR... |
| CVE-2023-40889 | CRITICAL | 9.8 | 1.5% | Aug 29, 2023 | A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes ... |
| CVE-2023-3646 | HIGH | 7.5 | 0.6% | Aug 29, 2023 | On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error ma... |
| CVE-2023-39616 | HIGH | 7.5 | 0.6% | Aug 29, 2023 | AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p... |
| CVE-2023-39615 | MEDIUM | 6.5 | 0.7% | Aug 29, 2023 | Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxm... |
| CVE-2023-24548 | MEDIUM | 6.5 | 0.5% | Aug 29, 2023 | On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tun... |
| CVE-2023-41376 | HIGH | 7.5 | 0.7% | Aug 29, 2023 | Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enab... |
| CVE-2023-41362 | HIGH | 7.2 | 1.6% | Aug 29, 2023 | MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use ... |
| CVE-2023-38802 | HIGH | 7.5 | 1.4% | Aug 29, 2023 | FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a craft... |
| CVE-2023-38283 | MEDIUM | 5.3 | 1.1% | Aug 29, 2023 | In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant r... |
| CVE-2023-0654 | LOW | 3.7 | 0.2% | Aug 29, 2023 | Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the ev... |
| CVE-2023-0238 | MEDIUM | 5.5 | 0.2% | Aug 29, 2023 | Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic... |
| CVE-2023-40787 | CRITICAL | 9.8 | 19.4% | Aug 29, 2023 | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks,... |
| CVE-2023-23774 | HIGH | 8.4 | 0.2% | Aug 29, 2023 | Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller expos... |
| CVE-2023-23773 | HIGH | 8.8 | 0.4% | Aug 29, 2023 | Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic sig... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now