2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21147HIGH7.8In lwis_i2c_device_disable of lwis_device_i2c.c, there is a possible UAF due to a logic error in the code. This could le...
CVE-2023-21146MEDIUM6.7there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with...
CVE-2023-21066CRITICAL9.8In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to r...
CVE-2023-2625HIGH8A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as...
CVE-2023-27866CRITICAL9.8IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver cod...
CVE-2023-34937HIGH7.5A stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS...
CVE-2023-34936HIGH7.5A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service ...
CVE-2023-34935HIGH7.5A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service ...
CVE-2023-34934HIGH7.5A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Servi...
CVE-2023-34933HIGH7.5A stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service...
CVE-2023-26615HIGH7.5D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleAction...
CVE-2023-20199MEDIUM6.6A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypa...
CVE-2023-20192HIGH7.7Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ...
CVE-2023-20188MEDIUM4.8A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus...
CVE-2023-20178HIGH7.8A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco S...
CVE-2023-20136MEDIUM6.5A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privilege...
CVE-2023-20120MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ...
CVE-2023-20119MEDIUM6.1A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, ...
CVE-2023-20116MEDIUM5.7A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and...
CVE-2023-20108HIGH7.5A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service ...
CVE-2023-20105MEDIUM6.5A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communicati...
CVE-2023-20028MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ...
CVE-2023-20006HIGH7.5A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Soft...
CVE-2023-3445MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.
CVE-2023-36467HIGH8.8AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now