2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30683LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without pe...
CVE-2023-30682LOW3.3Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API with...
CVE-2023-30681HIGH7.8An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1...
CVE-2023-30680HIGH7.8Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privi...
CVE-2023-30679HIGH7.8Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary cod...
CVE-2023-30654MEDIUM5.5Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to updat...
CVE-2023-36673HIGH7.3An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operatin...
CVE-2023-36672MEDIUM5.7An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the ...
CVE-2023-36671MEDIUM6.3An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the ...
CVE-2023-35838MEDIUM5.7The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a loc...
CVE-2023-33242HIGH8.1Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by ...
CVE-2023-33241CRITICAL9.1Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by...
CVE-2023-38348HIGH8.8A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.
CVE-2023-38347MEDIUM6.1An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbo...
CVE-2023-37068CRITICAL9.8Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, l...
CVE-2023-33469HIGH7.8In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2)...
CVE-2023-33468CRITICAL9.1KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables ...
CVE-2023-23347HIGH7.1HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise...
CVE-2023-39008CRITICAL9.8A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 ...
CVE-2023-39007CRITICAL9.6/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al...
CVE-2023-39006MEDIUM5.4The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before ...
CVE-2023-39005HIGH7.5Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4...
CVE-2023-39004CRITICAL9.8Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edit...
CVE-2023-39003HIGH7.5OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions...
CVE-2023-39002MEDIUM6.1A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now