2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24896MEDIUM5.4Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-36838MEDIUM5.5An Out-of-bounds Read vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series all...
CVE-2023-36833MEDIUM6.5A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36...
CVE-2023-28985HIGH7.5An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Ju...
CVE-2023-36832HIGH7.5An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Ser...
CVE-2023-35692HIGH7.8In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to...
CVE-2023-36831HIGH7.5An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filteri...
CVE-2023-36119Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-3673HIGH7.2 SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
CVE-2023-3434MEDIUM5.4Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. ...
CVE-2023-3433MEDIUM5.5The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts s...
CVE-2023-2975MEDIUM5.3Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries w...
CVE-2023-3672MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.
CVE-2023-3649MEDIUM5.5iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
CVE-2023-3648MEDIUM5.5Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or c...
CVE-2023-3514HIGH7.8Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali...
CVE-2023-3513HIGH7.8Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali...
CVE-2023-38286HIGH7.5Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, ...
CVE-2023-2082MEDIUM5.4The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions ...
CVE-2023-3668HIGH7.2Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
CVE-2023-37723CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37722CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37721CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37719CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37718CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now