2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38751MEDIUM4.3Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 ...
CVE-2023-4239MEDIUM6.5The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2...
CVE-2023-39910HIGH7.5The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Mil...
CVE-2023-39341LOW3.3"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, wh...
CVE-2023-39951MEDIUM6.5OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. O...
CVE-2023-39214HIGH8.1Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial ...
CVE-2023-39213CRITICAL9.8Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may all...
CVE-2023-39212MEDIUM5.5 Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denia...
CVE-2023-39211HIGH7.8Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an a...
CVE-2023-39210MEDIUM5.5Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user ...
CVE-2023-39209MEDIUM6.5Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an ...
CVE-2023-39086HIGH7.5ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
CVE-2023-36482MEDIUM4.3An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking i...
CVE-2023-36344HIGH7.8An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code vi...
CVE-2023-26961MEDIUM4.8Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attac...
CVE-2023-40042CRITICAL9.8TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so...
CVE-2023-40041CRITICAL9.8TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. A...
CVE-2023-39533HIGH7.5go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 maliciou...
CVE-2023-39518MEDIUM5.4social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Ve...
CVE-2023-38815Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-40042. Reason: This candidate is a reservation d...
CVE-2023-38180HIGH7.5.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-36899HIGH8.8ASP.NET Elevation of Privilege Vulnerability
CVE-2023-36873MEDIUM5.9.NET Framework Spoofing Vulnerability
CVE-2023-35391HIGH7.5ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
CVE-2023-3894HIGH7.5Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the par...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now