2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36081MEDIUM5.4Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to exe...
CVE-2023-29409MEDIUM5.3Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signat...
CVE-2023-29408MEDIUM6.5The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit thi...
CVE-2023-29407MEDIUM6.5A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very...
CVE-2023-3470MEDIUM6.1 Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ac...
CVE-2023-38423MEDIUM5.4 A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allow...
CVE-2023-38419MEDIUM4.3An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending un...
CVE-2023-38418HIGH7.8 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati...
CVE-2023-38138MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ...
CVE-2023-36858MEDIUM5.5 An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an...
CVE-2023-36494MEDIUM4.4 Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of ...
CVE-2023-38330MEDIUM5.3OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administrat...
CVE-2023-23476MEDIUM6.5IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic...
CVE-2023-33383MEDIUM5.3Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t...
CVE-2023-33257MEDIUM5.4Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
CVE-2023-26317CRITICAL9.8Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filteri...
CVE-2023-26316MEDIUM6.1A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whi...
CVE-2023-26451HIGH7.5Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization ...
CVE-2023-26450MEDIUM5.4The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious scrip...
CVE-2023-26449MEDIUM5.4The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script...
CVE-2023-26448MEDIUM5.4Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handler...
CVE-2023-26447MEDIUM5.4The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controlla...
CVE-2023-26446MEDIUM5.4The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script c...
CVE-2023-26445MEDIUM5.4Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets proce...
CVE-2023-26443CRITICAL9.8Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now