2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34114MEDIUM6.5Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authent...
CVE-2023-27836CRITICAL9.8TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the deviceP...
CVE-2023-3224CRITICAL9.8Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
CVE-2023-3217HIGH8.8Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap c...
CVE-2023-3216HIGH8.8Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-3215HIGH8.8Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap ...
CVE-2023-3214HIGH8.8Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially ex...
CVE-2023-34122Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE...
CVE-2023-34121HIGH8.8Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may all...
CVE-2023-34120HIGH7.8Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14....
CVE-2023-34113Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE...
CVE-2023-28603HIGH7.1Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may pote...
CVE-2023-28602HIGH7.7Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A m...
CVE-2023-28601MEDIUM6.5Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buf...
CVE-2023-28600MEDIUM5.4Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to...
CVE-2023-1707HIGH7.5Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure whe...
CVE-2023-34249CRITICAL9.8benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is...
CVE-2023-34247MEDIUM4.1Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package version...
CVE-2023-33620MEDIUM5.9GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdro...
CVE-2023-31541CRITICAL9.8A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3...
CVE-2023-31439MEDIUM5.3An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then...
CVE-2023-31438MEDIUM5.3An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that...
CVE-2023-31437MEDIUM5.3An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all exist...
CVE-2023-30179HIGH7.2CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twi...
CVE-2023-28599MEDIUM4.3Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now