2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34394HIGH7.8 In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d...
CVE-2023-32657HIGH7.5 Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with...
CVE-2023-3782MEDIUM5.9DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can p...
CVE-2023-26217HIGH8.8The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerabili...
CVE-2023-3722CRITICAL9.8An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remo...
CVE-2023-37899HIGH7.5Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socke...
CVE-2023-37276HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled w...
CVE-2023-3674LOW2.8A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when ...
CVE-2023-3467HIGH8Privilege Escalation to root administrator (nsroot)
CVE-2023-3466MEDIUM6.1Reflected Cross-Site Scripting (XSS)
CVE-2023-37733MEDIUM6.1An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted H...
CVE-2023-3519CRITICAL9.8Unauthenticated remote code execution
CVE-2023-37748MEDIUM5.5ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
CVE-2023-32263MEDIUM5.7 A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability co...
CVE-2023-32262MEDIUM6.5 A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability al...
CVE-2023-32261MEDIUM6.5 A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability al...
CVE-2023-25839HIGH7 There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow...
CVE-2023-25838HIGH7.5 There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, ...
CVE-2023-3638CRITICAL9.8In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
CVE-2023-34034CRITICAL9.8Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spr...
CVE-2023-30799HIGH7.2MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A re...
CVE-2023-3463CRITICAL9.8 All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sour...
CVE-2023-33876HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially cra...
CVE-2023-33866HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By ...
CVE-2023-32664HIGH7.8A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now