2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4429HIGH8.8Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ...
CVE-2023-4428HIGH8.1Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out ...
CVE-2023-4427HIGH8.1Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out o...
CVE-2023-40370MEDIUM5.3 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script conten...
CVE-2023-39026HIGH7.5Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t...
CVE-2023-38734CRITICAL9.8 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege a...
CVE-2023-38733MEDIUM4.3 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated us...
CVE-2023-33850HIGH7.5IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in...
CVE-2023-4475MEDIUM5.5An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file r...
CVE-2023-4212MEDIUM6.8 ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to ...
CVE-2023-3699MEDIUM5.5An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users...
CVE-2023-39599MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted pay...
CVE-2023-39141HIGH7.5webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
CVE-2023-38996MEDIUM6.7An issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via...
CVE-2023-38732MEDIUM4.3 IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive informa...
CVE-2023-38668MEDIUM5.5Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).
CVE-2023-38667MEDIUM5.5Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.
CVE-2023-38666MEDIUM5.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in...
CVE-2023-38665MEDIUM5.5Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).
CVE-2023-37440MEDIUM5.3A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2023-37439MEDIUM6.1Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37438MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37437MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37436MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...
CVE-2023-37435MEDIUM6.5Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now