2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36081 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to exe... |
| CVE-2023-29409 | MEDIUM | 5.3 | 1.3% | Aug 2, 2023 | Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signat... |
| CVE-2023-29408 | MEDIUM | 6.5 | 0.9% | Aug 2, 2023 | The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit thi... |
| CVE-2023-29407 | MEDIUM | 6.5 | 0.8% | Aug 2, 2023 | A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very... |
| CVE-2023-3470 | MEDIUM | 6.1 | 0.2% | Aug 2, 2023 | Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ac... |
| CVE-2023-38423 | MEDIUM | 5.4 | 0.3% | Aug 2, 2023 | A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allow... |
| CVE-2023-38419 | MEDIUM | 4.3 | 0.5% | Aug 2, 2023 | An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending un... |
| CVE-2023-38418 | HIGH | 7.8 | 0.1% | Aug 2, 2023 | The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati... |
| CVE-2023-38138 | MEDIUM | 6.1 | 0.3% | Aug 2, 2023 | A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ... |
| CVE-2023-36858 | MEDIUM | 5.5 | 0.1% | Aug 2, 2023 | An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an... |
| CVE-2023-36494 | MEDIUM | 4.4 | 0.2% | Aug 2, 2023 | Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of ... |
| CVE-2023-38330 | MEDIUM | 5.3 | 0.4% | Aug 2, 2023 | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administrat... |
| CVE-2023-23476 | MEDIUM | 6.5 | 0.4% | Aug 2, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic... |
| CVE-2023-33383 | MEDIUM | 5.3 | 2.5% | Aug 2, 2023 | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t... |
| CVE-2023-33257 | MEDIUM | 5.4 | 0.3% | Aug 2, 2023 | Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat. |
| CVE-2023-26317 | CRITICAL | 9.8 | 0.9% | Aug 2, 2023 | Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filteri... |
| CVE-2023-26316 | MEDIUM | 6.1 | 0.3% | Aug 2, 2023 | A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whi... |
| CVE-2023-26451 | HIGH | 7.5 | 1.0% | Aug 2, 2023 | Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization ... |
| CVE-2023-26450 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious scrip... |
| CVE-2023-26449 | MEDIUM | 5.4 | 0.7% | Aug 2, 2023 | The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script... |
| CVE-2023-26448 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handler... |
| CVE-2023-26447 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controlla... |
| CVE-2023-26446 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script c... |
| CVE-2023-26445 | MEDIUM | 5.4 | 0.6% | Aug 2, 2023 | Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets proce... |
| CVE-2023-26443 | CRITICAL | 9.8 | 0.7% | Aug 2, 2023 | Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now