2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36255HIGH8.8An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar...
CVE-2023-36212HIGH8.8File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file...
CVE-2023-26979LOW3.1Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the...
CVE-2023-4078HIGH8.8Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ...
CVE-2023-4077HIGH8.8Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ...
CVE-2023-4076HIGH8.8Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap ...
CVE-2023-4075HIGH8.8Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap co...
CVE-2023-4074HIGH8.8Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentiall...
CVE-2023-4073HIGH8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potent...
CVE-2023-4072HIGH8.8Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially ...
CVE-2023-4071HIGH8.8Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploi...
CVE-2023-4070HIGH8.1Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write ...
CVE-2023-4069HIGH8.8Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-4068HIGH8.1Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write ...
CVE-2023-36082CRITICAL9.8An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP an...
CVE-2023-33371CRITICAL9.8Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens...
CVE-2023-33370HIGH7.5An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the ma...
CVE-2023-33369CRITICAL9.1A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary ...
CVE-2023-33368MEDIUM6.5Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to us...
CVE-2023-3329MEDIUM6.5SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative ...
CVE-2023-39114MEDIUM5.5ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibS...
CVE-2023-39113MEDIUM5.5ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulne...
CVE-2023-1935CRITICAL9.4ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized...
CVE-2023-1437CRITICAL9.8All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments ...
CVE-2023-3978MEDIUM6.1Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now