2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38197HIGH7.5An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinit...
CVE-2023-37568HIGH8ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjac...
CVE-2023-37567CRITICAL9.8Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to e...
CVE-2023-37566HIGH8Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attac...
CVE-2023-37561MEDIUM6.1Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthentic...
CVE-2023-37560MEDIUM6.1Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote un...
CVE-2023-34130CRITICAL9.8SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data....
CVE-2023-34129HIGH8.8Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analyt...
CVE-2023-2190MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions st...
CVE-2023-34128CRITICAL9.8Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: ...
CVE-2023-34127HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM...
CVE-2023-34126HIGH8.8Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesyst...
CVE-2023-34125MEDIUM6.5Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the unde...
CVE-2023-34124CRITICAL9.8The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio...
CVE-2023-21260MEDIUM5.5In notification access permission dialog box, malicious application can embedded a very long service label that overflow...
CVE-2023-35694HIGH7.5In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds c...
CVE-2023-35693MEDIUM6.7In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to lo...
CVE-2023-35691HIGH7.2there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with S...
CVE-2023-34123HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-S...
CVE-2023-21400MEDIUM6.7In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could l...
CVE-2023-21399HIGH7.8there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local es...
CVE-2023-21262LOW3.1In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy ...
CVE-2023-21261Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-21257HIGH7.8In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile...
CVE-2023-21256HIGH7.8In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic err...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now