2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34932HIGH7.5A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (...
CVE-2023-34931HIGH7.5A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service...
CVE-2023-34930HIGH7.5A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (Do...
CVE-2023-34929HIGH7.5A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS...
CVE-2023-34928HIGH7.5A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service ...
CVE-2023-30259MEDIUM5.5A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information v...
CVE-2023-1295HIGH7A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's vers...
CVE-2023-3034MEDIUM6.1Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
CVE-2023-32623CRITICAL9.1Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to de...
CVE-2023-26134CRITICAL9.8Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported ...
CVE-2023-3407MEDIUM4.3The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40....
CVE-2023-1844MEDIUM4.3The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capabil...
CVE-2023-3427MEDIUM4.3The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2023-3333HIGH7.2Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG26...
CVE-2023-3332MEDIUM4.8Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26...
CVE-2023-3331MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26...
CVE-2023-3330MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, ...
CVE-2023-3327Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-35823. Reason: This candidate is a reservation d...
CVE-2023-25002HIGH7.8A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of thi...
CVE-2023-25001HIGH7.8A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exp...
CVE-2023-36464MEDIUM5.5pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an inf...
CVE-2023-3436LOW3.3Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
CVE-2023-36463MEDIUM6.1Meldekarten generator is an open source project to create a program, running locally in the browser without the need for...
CVE-2023-30993HIGH7.5IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to...
CVE-2023-29068HIGH7.8A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vul...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now