2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34142HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manage...
CVE-2023-31998HIGH7.5A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to sa...
CVE-2023-38432CRITICAL9.1An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relat...
CVE-2023-38431CRITICAL9.1An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the rela...
CVE-2023-38430CRITICAL9.1An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading t...
CVE-2023-38429CRITICAL9.8An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memo...
CVE-2023-38428CRITICAL9.1An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserNa...
CVE-2023-38427CRITICAL9.8An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and ...
CVE-2023-38426CRITICAL9.1An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when...
CVE-2023-37850Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-37479HIGH7.5Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted ...
CVE-2023-3724HIGH8.8If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a m...
CVE-2023-38409MEDIUM5.5An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because...
CVE-2023-37476HIGH7.8OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file ca...
CVE-2023-38405HIGH7.5On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash...
CVE-2023-38404HIGH8.8The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attac...
CVE-2023-38403HIGH7.5iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
CVE-2023-37266CRITICAL9.8CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features t...
CVE-2023-37265CRITICAL9.8CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers ca...
CVE-2023-37781MEDIUM6.5An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted ...
CVE-2023-37770MEDIUM5.5faust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.c...
CVE-2023-37769MEDIUM6.5stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixma...
CVE-2023-37461CRITICAL9.8Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a rel...
CVE-2023-28864MEDIUM5.5Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup wor...
CVE-2023-37791CRITICAL9.8D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now