2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22659 | HIGH | 7.2 | 3.6% | Jul 6, 2023 | An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0... |
| CVE-2023-22653 | HIGH | 8.8 | 6.8% | Jul 6, 2023 | An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0... |
| CVE-2023-22371 | HIGH | 8.1 | 3.3% | Jul 6, 2023 | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2... |
| CVE-2023-22365 | HIGH | 7.2 | 2.1% | Jul 6, 2023 | An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32... |
| CVE-2023-22319 | CRITICAL | 9.8 | 0.8% | Jul 6, 2023 | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specia... |
| CVE-2023-22306 | HIGH | 7.2 | 3.4% | Jul 6, 2023 | An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5.... |
| CVE-2023-22299 | HIGH | 8.8 | 3.5% | Jul 6, 2023 | An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. ... |
| CVE-2023-36995 | MEDIUM | 6.1 | 0.4% | Jul 6, 2023 | TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, ... |
| CVE-2023-36968 | HIGH | 7.2 | 0.7% | Jul 6, 2023 | A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by ... |
| CVE-2023-36189 | HIGH | 7.5 | 0.9% | Jul 6, 2023 | SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via th... |
| CVE-2023-36188 | CRITICAL | 9.8 | 1.6% | Jul 6, 2023 | An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Pyth... |
| CVE-2023-35937 | HIGH | 8.8 | 0.6% | Jul 6, 2023 | Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere... |
| CVE-2023-3456 | MEDIUM | 5.3 | 0.3% | Jul 6, 2023 | Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability ... |
| CVE-2023-37245 | CRITICAL | 9.1 | 0.4% | Jul 6, 2023 | Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the ... |
| CVE-2023-37242 | CRITICAL | 9.8 | 0.4% | Jul 6, 2023 | Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnera... |
| CVE-2023-37241 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to r... |
| CVE-2023-37240 | CRITICAL | 9.1 | 0.4% | Jul 6, 2023 | Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vul... |
| CVE-2023-37239 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit thi... |
| CVE-2023-37238 | MEDIUM | 5.3 | 0.3% | Jul 6, 2023 | Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module.... |
| CVE-2023-34164 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation ... |
| CVE-2023-1695 | HIGH | 7.5 | 0.3% | Jul 6, 2023 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab... |
| CVE-2023-1691 | HIGH | 7.5 | 0.3% | Jul 6, 2023 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab... |
| CVE-2023-3523 | HIGH | 7.1 | 0.3% | Jul 6, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. |
| CVE-2023-26138 | MEDIUM | 4.3 | 0.4% | Jul 6, 2023 | All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to... |
| CVE-2023-26137 | MEDIUM | 6.1 | 0.4% | Jul 6, 2023 | All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now