2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22659HIGH7.2An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0...
CVE-2023-22653HIGH8.8An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0...
CVE-2023-22371HIGH8.1An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2...
CVE-2023-22365HIGH7.2An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32...
CVE-2023-22319CRITICAL9.8A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specia...
CVE-2023-22306HIGH7.2An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5....
CVE-2023-22299HIGH8.8An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. ...
CVE-2023-36995MEDIUM6.1TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, ...
CVE-2023-36968HIGH7.2A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by ...
CVE-2023-36189HIGH7.5SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via th...
CVE-2023-36188CRITICAL9.8An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Pyth...
CVE-2023-35937HIGH8.8Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere...
CVE-2023-3456MEDIUM5.3Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability ...
CVE-2023-37245CRITICAL9.1Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the ...
CVE-2023-37242CRITICAL9.8Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnera...
CVE-2023-37241HIGH7.5Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to r...
CVE-2023-37240CRITICAL9.1 Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vul...
CVE-2023-37239HIGH7.5Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit thi...
CVE-2023-37238MEDIUM5.3Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module....
CVE-2023-34164HIGH7.5Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation ...
CVE-2023-1695HIGH7.5Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab...
CVE-2023-1691HIGH7.5Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab...
CVE-2023-3523HIGH7.1Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
CVE-2023-26138MEDIUM4.3All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to...
CVE-2023-26137MEDIUM6.1All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now