2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34394 | HIGH | 7.8 | 0.2% | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d... |
| CVE-2023-32657 | HIGH | 7.5 | 0.4% | Jul 19, 2023 | Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with... |
| CVE-2023-3782 | MEDIUM | 5.9 | 0.6% | Jul 19, 2023 | DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can p... |
| CVE-2023-26217 | HIGH | 8.8 | 0.6% | Jul 19, 2023 | The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerabili... |
| CVE-2023-3722 | CRITICAL | 9.8 | 3.3% | Jul 19, 2023 | An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remo... |
| CVE-2023-37899 | HIGH | 7.5 | 1.0% | Jul 19, 2023 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socke... |
| CVE-2023-37276 | HIGH | 7.5 | 1.4% | Jul 19, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled w... |
| CVE-2023-3674 | LOW | 2.8 | 0.2% | Jul 19, 2023 | A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when ... |
| CVE-2023-3467 | HIGH | 8 | 2.1% | Jul 19, 2023 | Privilege Escalation to root administrator (nsroot) |
| CVE-2023-3466 | MEDIUM | 6.1 | 3.0% | Jul 19, 2023 | Reflected Cross-Site Scripting (XSS) |
| CVE-2023-37733 | MEDIUM | 6.1 | 0.5% | Jul 19, 2023 | An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted H... |
| CVE-2023-3519 | CRITICAL | 9.8 | 99.7% | Jul 19, 2023 | Unauthenticated remote code execution |
| CVE-2023-37748 | MEDIUM | 5.5 | 0.3% | Jul 19, 2023 | ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c. |
| CVE-2023-32263 | MEDIUM | 5.7 | 0.3% | Jul 19, 2023 | A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability co... |
| CVE-2023-32262 | MEDIUM | 6.5 | 0.8% | Jul 19, 2023 | A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability al... |
| CVE-2023-32261 | MEDIUM | 6.5 | 0.6% | Jul 19, 2023 | A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability al... |
| CVE-2023-25839 | HIGH | 7 | 0.2% | Jul 19, 2023 | There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow... |
| CVE-2023-25838 | HIGH | 7.5 | 0.5% | Jul 19, 2023 | There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, ... |
| CVE-2023-3638 | CRITICAL | 9.8 | 0.6% | Jul 19, 2023 | In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. |
| CVE-2023-34034 | CRITICAL | 9.8 | 3.5% | Jul 19, 2023 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spr... |
| CVE-2023-30799 | HIGH | 7.2 | 1.3% | Jul 19, 2023 | MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A re... |
| CVE-2023-3463 | CRITICAL | 9.8 | 0.4% | Jul 19, 2023 | All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sour... |
| CVE-2023-33876 | HIGH | 8.8 | 0.9% | Jul 19, 2023 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially cra... |
| CVE-2023-33866 | HIGH | 8.8 | 0.9% | Jul 19, 2023 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By ... |
| CVE-2023-32664 | HIGH | 7.8 | 0.9% | Jul 19, 2023 | A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now