2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39707MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attack...
CVE-2023-39600MEDIUM6.1IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-37249HIGH8.8Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell...
CVE-2023-36199HIGH7.5An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGene...
CVE-2023-36198HIGH7.5Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the ...
CVE-2023-24621HIGH7.8An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by defau...
CVE-2023-24620MEDIUM5.5An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expans...
CVE-2023-25848MEDIUM5.3ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz...
CVE-2023-38201MEDIUM6.5A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent regi...
CVE-2023-40798HIGH8.8In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input pa...
CVE-2023-40797HIGH8.8In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting i...
CVE-2023-40796HIGH7.8Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
CVE-2023-4534MEDIUM6.1A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is a...
CVE-2023-40915HIGH7.5Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This v...
CVE-2023-40802MEDIUM6.5The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authenticati...
CVE-2023-40801HIGH8.8The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerabilit...
CVE-2023-40800HIGH8.8The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication ...
CVE-2023-40799CRITICAL9.8Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.
CVE-2023-41167MEDIUM4.8@webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to rend...
CVE-2023-39742MEDIUM5.5giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.
CVE-2023-41250MEDIUM6.1In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
CVE-2023-41249MEDIUM6.1In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
CVE-2023-41248MEDIUM5.4In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
CVE-2023-32797MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution video carousel slider with lightbo...
CVE-2023-32603MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now