2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37717CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were...
CVE-2023-37716CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were...
CVE-2023-37715CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37714CRITICAL9.8Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter...
CVE-2023-37466CRITICAL10vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for prod...
CVE-2023-37837MEDIUM6.5libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebit...
CVE-2023-37836MEDIUM6.5libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. Thi...
CVE-2023-37278CRITICAL9.1GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2023-37275MEDIUM4.3Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GP...
CVE-2023-37274HIGH7.8Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-G...
CVE-2023-37273HIGH8.8Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Aut...
CVE-2023-37272MEDIUM5.4JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation ...
CVE-2023-37849MEDIUM6.5A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute ar...
CVE-2023-37839CRITICAL9.8An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute ...
CVE-2023-37599HIGH7.5An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
CVE-2023-37598MEDIUM4.5A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of...
CVE-2023-37468MEDIUM5.5Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LD...
CVE-2023-36473MEDIUM6.1Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X...
CVE-2023-35945HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk...
CVE-2023-37463HIGH7.5cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syn...
CVE-2023-30565LOW3.5An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
CVE-2023-30564MEDIUM6.9Alaris Systems Manager does not perform input validation during the Device Import Function.
CVE-2023-30563HIGH8.2A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
CVE-2023-30562MEDIUM6.7A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
CVE-2023-30561MEDIUM6.1The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now