2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38197 | HIGH | 7.5 | 1.1% | Jul 13, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinit... |
| CVE-2023-37568 | HIGH | 8 | 0.4% | Jul 13, 2023 | ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjac... |
| CVE-2023-37567 | CRITICAL | 9.8 | 1.8% | Jul 13, 2023 | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to e... |
| CVE-2023-37566 | HIGH | 8 | 1.0% | Jul 13, 2023 | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attac... |
| CVE-2023-37561 | MEDIUM | 6.1 | 0.4% | Jul 13, 2023 | Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthentic... |
| CVE-2023-37560 | MEDIUM | 6.1 | 0.4% | Jul 13, 2023 | Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote un... |
| CVE-2023-34130 | CRITICAL | 9.8 | 0.3% | Jul 13, 2023 | SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data.... |
| CVE-2023-34129 | HIGH | 8.8 | 42.9% | Jul 13, 2023 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analyt... |
| CVE-2023-2190 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions st... |
| CVE-2023-34128 | CRITICAL | 9.8 | 0.6% | Jul 13, 2023 | Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: ... |
| CVE-2023-34127 | HIGH | 8.8 | 86.7% | Jul 13, 2023 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM... |
| CVE-2023-34126 | HIGH | 8.8 | 0.6% | Jul 13, 2023 | Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesyst... |
| CVE-2023-34125 | MEDIUM | 6.5 | 22.7% | Jul 13, 2023 | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the unde... |
| CVE-2023-34124 | CRITICAL | 9.8 | 40.9% | Jul 13, 2023 | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio... |
| CVE-2023-21260 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | In notification access permission dialog box, malicious application can embedded a very long service label that overflow... |
| CVE-2023-35694 | HIGH | 7.5 | 0.3% | Jul 13, 2023 | In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds c... |
| CVE-2023-35693 | MEDIUM | 6.7 | 0.1% | Jul 13, 2023 | In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to lo... |
| CVE-2023-35691 | HIGH | 7.2 | 0.4% | Jul 13, 2023 | there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with S... |
| CVE-2023-34123 | HIGH | 7.5 | 0.7% | Jul 13, 2023 | Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-S... |
| CVE-2023-21400 | MEDIUM | 6.7 | 0.3% | Jul 13, 2023 | In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could l... |
| CVE-2023-21399 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local es... |
| CVE-2023-21262 | LOW | 3.1 | 0.1% | Jul 13, 2023 | In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy ... |
| CVE-2023-21261 | — | — | — | Jul 13, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-21257 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile... |
| CVE-2023-21256 | HIGH | 7.8 | 0.1% | Jul 13, 2023 | In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic err... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now