2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28323CRITICAL9.8A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to...
CVE-2023-22814CRITICAL9.8An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow ...
CVE-2023-36812CRITICAL9.8OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Exec...
CVE-2023-36144HIGH7.5An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo...
CVE-2023-3493HIGH8Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
CVE-2023-3491HIGH8.8Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
CVE-2023-3490CRITICAL9.8 SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
CVE-2023-3338MEDIUM6.5A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a rem...
CVE-2023-3117Rejected reason: Duplicate of CVE-2023-3390.
CVE-2023-33298HIGH7.8com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell m...
CVE-2023-2908MEDIUM5.5A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a craft...
CVE-2023-29241HIGH7.1Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configu...
CVE-2023-22816HIGH8.8A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that...
CVE-2023-22815MEDIUM6.7Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an ...
CVE-2023-1206MEDIUM5.7A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user...
CVE-2023-35947HIGH8.1Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions...
CVE-2023-35946MEDIUM5.5Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a...
CVE-2023-29147MEDIUM5.5In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, be...
CVE-2023-31543CRITICAL9.8A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted P...
CVE-2023-29145HIGH7.8The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by exec...
CVE-2023-27469HIGH7.1Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message i...
CVE-2023-37365MEDIUM6.5Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
CVE-2023-36810MEDIUM6.5pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An ...
CVE-2023-36807MEDIUM6.5pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In ...
CVE-2023-36477MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now