2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30683 | LOW | 3.3 | 0.1% | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without pe... |
| CVE-2023-30682 | LOW | 3.3 | 0.1% | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API with... |
| CVE-2023-30681 | HIGH | 7.8 | 0.2% | Aug 10, 2023 | An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1... |
| CVE-2023-30680 | HIGH | 7.8 | 0.2% | Aug 10, 2023 | Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privi... |
| CVE-2023-30679 | HIGH | 7.8 | 0.1% | Aug 10, 2023 | Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary cod... |
| CVE-2023-30654 | MEDIUM | 5.5 | 0.2% | Aug 10, 2023 | Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to updat... |
| CVE-2023-36673 | HIGH | 7.3 | 0.6% | Aug 9, 2023 | An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operatin... |
| CVE-2023-36672 | MEDIUM | 5.7 | 0.7% | Aug 9, 2023 | An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the ... |
| CVE-2023-36671 | MEDIUM | 6.3 | 0.3% | Aug 9, 2023 | An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the ... |
| CVE-2023-35838 | MEDIUM | 5.7 | 0.8% | Aug 9, 2023 | The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a loc... |
| CVE-2023-33242 | HIGH | 8.1 | 1.1% | Aug 9, 2023 | Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by ... |
| CVE-2023-33241 | CRITICAL | 9.1 | 1.0% | Aug 9, 2023 | Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by... |
| CVE-2023-38348 | HIGH | 8.8 | 0.3% | Aug 9, 2023 | A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1. |
| CVE-2023-38347 | MEDIUM | 6.1 | 0.4% | Aug 9, 2023 | An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbo... |
| CVE-2023-37068 | CRITICAL | 9.8 | 0.9% | Aug 9, 2023 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, l... |
| CVE-2023-33469 | HIGH | 7.8 | 0.3% | Aug 9, 2023 | In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2)... |
| CVE-2023-33468 | CRITICAL | 9.1 | 0.6% | Aug 9, 2023 | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables ... |
| CVE-2023-23347 | HIGH | 7.1 | 0.1% | Aug 9, 2023 | HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise... |
| CVE-2023-39008 | CRITICAL | 9.8 | 2.6% | Aug 9, 2023 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 ... |
| CVE-2023-39007 | CRITICAL | 9.6 | 2.3% | Aug 9, 2023 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al... |
| CVE-2023-39006 | MEDIUM | 5.4 | 0.4% | Aug 9, 2023 | The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before ... |
| CVE-2023-39005 | HIGH | 7.5 | 0.6% | Aug 9, 2023 | Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4... |
| CVE-2023-39004 | CRITICAL | 9.8 | 0.8% | Aug 9, 2023 | Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edit... |
| CVE-2023-39003 | HIGH | 7.5 | 0.7% | Aug 9, 2023 | OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions... |
| CVE-2023-39002 | MEDIUM | 6.1 | 1.2% | Aug 9, 2023 | A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now