2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32437HIGH8.6The issue was addressed with improvements to the file handling protocol. This issue is fixed in iOS 16.6 and iPadOS 16.6...
CVE-2023-32433HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS ...
CVE-2023-32381HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS ...
CVE-2023-28014MEDIUM5.4HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scrip...
CVE-2023-28012HIGH8.8HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell comma...
CVE-2023-3451Rejected reason: Duplicate CVE. Please use CVE-2023-32297.
CVE-2023-28013MEDIUM6.1HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering craf...
CVE-2023-38285HIGH7.5Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
CVE-2023-37732MEDIUM5.5Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacke...
CVE-2023-37692MEDIUM5.4An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted fi...
CVE-2023-32001Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem ...
CVE-2023-30367HIGH7.5Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage mult...
CVE-2023-37624MEDIUM6.1Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnera...
CVE-2023-37623MEDIUM4.8Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/Ty...
CVE-2023-33802MEDIUM5.5A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text fil...
CVE-2023-31466MEDIUM5.4An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance re...
CVE-2023-31465CRITICAL9.8An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st...
CVE-2023-3442HIGH7.5A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 th...
CVE-2023-3414MEDIUM6.5A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38...
CVE-2023-3242MEDIUM5.9Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows ...
CVE-2023-30949MEDIUM5.3A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which ...
CVE-2023-30577HIGH7.8AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for r...
CVE-2023-3622MEDIUM4.3 Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary r...
CVE-2023-33308CRITICAL9.8A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 ...
CVE-2023-33229LOW3.5The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now