2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37717 | CRITICAL | 9.8 | 0.8% | Jul 14, 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were... |
| CVE-2023-37716 | CRITICAL | 9.8 | 0.8% | Jul 14, 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were... |
| CVE-2023-37715 | CRITICAL | 9.8 | 0.8% | Jul 14, 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter... |
| CVE-2023-37714 | CRITICAL | 9.8 | 0.8% | Jul 14, 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter... |
| CVE-2023-37466 | CRITICAL | 10 | 2.3% | Jul 14, 2023 | vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for prod... |
| CVE-2023-37837 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebit... |
| CVE-2023-37836 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. Thi... |
| CVE-2023-37278 | CRITICAL | 9.1 | 0.6% | Jul 13, 2023 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2023-37275 | MEDIUM | 4.3 | 0.4% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GP... |
| CVE-2023-37274 | HIGH | 7.8 | 0.3% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-G... |
| CVE-2023-37273 | HIGH | 8.8 | 0.3% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Aut... |
| CVE-2023-37272 | MEDIUM | 5.4 | 0.3% | Jul 13, 2023 | JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation ... |
| CVE-2023-37849 | MEDIUM | 6.5 | 0.4% | Jul 13, 2023 | A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute ar... |
| CVE-2023-37839 | CRITICAL | 9.8 | 1.0% | Jul 13, 2023 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute ... |
| CVE-2023-37599 | HIGH | 7.5 | 3.0% | Jul 13, 2023 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory |
| CVE-2023-37598 | MEDIUM | 4.5 | 0.5% | Jul 13, 2023 | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of... |
| CVE-2023-37468 | MEDIUM | 5.5 | 0.2% | Jul 13, 2023 | Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LD... |
| CVE-2023-36473 | MEDIUM | 6.1 | 0.3% | Jul 13, 2023 | Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X... |
| CVE-2023-35945 | HIGH | 7.5 | 1.1% | Jul 13, 2023 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk... |
| CVE-2023-37463 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syn... |
| CVE-2023-30565 | LOW | 3.5 | 0.1% | Jul 13, 2023 | An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker. |
| CVE-2023-30564 | MEDIUM | 6.9 | 0.3% | Jul 13, 2023 | Alaris Systems Manager does not perform input validation during the Device Import Function. |
| CVE-2023-30563 | HIGH | 8.2 | 0.4% | Jul 13, 2023 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. |
| CVE-2023-30562 | MEDIUM | 6.7 | 0.2% | Jul 13, 2023 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. |
| CVE-2023-30561 | MEDIUM | 6.1 | 0.2% | Jul 13, 2023 | The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now