2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33515MEDIUM5.4SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.
CVE-2023-31746CRITICAL9.8There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated ...
CVE-2023-30150CRITICAL9.8PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.
CVE-2023-26965MEDIUM5.5loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
CVE-2023-1329CRITICAL9.8A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability m...
CVE-2023-34367MEDIUM6.5Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows unti...
CVE-2023-30082HIGH7.5A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 cha...
CVE-2023-26062HIGH7.8A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, ...
CVE-2023-25434HIGH8.8libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
CVE-2023-25369HIGH7.5Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Denial of Service on the user interface triggered by malfo...
CVE-2023-25368HIGH7.5Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can ...
CVE-2023-31671CRITICAL9.8PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postPro...
CVE-2023-2976HIGH7.1Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to ...
CVE-2023-34095CRITICAL9.8cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1....
CVE-2023-25367CRITICAL9.8Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with ...
CVE-2023-0010MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software...
CVE-2023-0009HIGH7.8A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local u...
CVE-2023-34868HIGH7.5Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start...
CVE-2023-34867HIGH7.5Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at ...
CVE-2023-34540CRITICAL9.8Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPI...
CVE-2023-34101CRITICAL9.1Contiki-NG is an operating system for internet of things devices. In version 4.8 and prior, when processing ICMP DAO pac...
CVE-2023-32031HIGH8.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-32030HIGH7.5.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-32024LOW3Microsoft Power Apps Spoofing Vulnerability
CVE-2023-29337HIGH7.1NuGet Client Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now