2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36255 | HIGH | 8.8 | 57.4% | Aug 3, 2023 | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar... |
| CVE-2023-36212 | HIGH | 8.8 | 23.7% | Aug 3, 2023 | File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file... |
| CVE-2023-26979 | LOW | 3.1 | 0.2% | Aug 3, 2023 | Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the... |
| CVE-2023-4078 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ... |
| CVE-2023-4077 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ... |
| CVE-2023-4076 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-4075 | HIGH | 8.8 | 1.2% | Aug 3, 2023 | Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap co... |
| CVE-2023-4074 | HIGH | 8.8 | 1.1% | Aug 3, 2023 | Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentiall... |
| CVE-2023-4073 | HIGH | 8.8 | 1.3% | Aug 3, 2023 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potent... |
| CVE-2023-4072 | HIGH | 8.8 | 1.3% | Aug 3, 2023 | Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially ... |
| CVE-2023-4071 | HIGH | 8.8 | 1.3% | Aug 3, 2023 | Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploi... |
| CVE-2023-4070 | HIGH | 8.1 | 1.4% | Aug 3, 2023 | Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write ... |
| CVE-2023-4069 | HIGH | 8.8 | 24.1% | Aug 3, 2023 | Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-4068 | HIGH | 8.1 | 15.5% | Aug 3, 2023 | Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write ... |
| CVE-2023-36082 | CRITICAL | 9.8 | 1.0% | Aug 3, 2023 | An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP an... |
| CVE-2023-33371 | CRITICAL | 9.8 | 0.9% | Aug 3, 2023 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens... |
| CVE-2023-33370 | HIGH | 7.5 | 0.6% | Aug 3, 2023 | An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the ma... |
| CVE-2023-33369 | CRITICAL | 9.1 | 0.7% | Aug 3, 2023 | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary ... |
| CVE-2023-33368 | MEDIUM | 6.5 | 0.5% | Aug 3, 2023 | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to us... |
| CVE-2023-3329 | MEDIUM | 6.5 | 1.0% | Aug 2, 2023 | SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative ... |
| CVE-2023-39114 | MEDIUM | 5.5 | 0.3% | Aug 2, 2023 | ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibS... |
| CVE-2023-39113 | MEDIUM | 5.5 | 0.3% | Aug 2, 2023 | ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulne... |
| CVE-2023-1935 | CRITICAL | 9.4 | 0.5% | Aug 2, 2023 | ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized... |
| CVE-2023-1437 | CRITICAL | 9.8 | 2.8% | Aug 2, 2023 | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments ... |
| CVE-2023-3978 | MEDIUM | 6.1 | 0.8% | Aug 2, 2023 | Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now