2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34114 | MEDIUM | 6.5 | 1.0% | Jun 13, 2023 | Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authent... |
| CVE-2023-27836 | CRITICAL | 9.8 | 2.4% | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the deviceP... |
| CVE-2023-3224 | CRITICAL | 9.8 | 58.6% | Jun 13, 2023 | Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. |
| CVE-2023-3217 | HIGH | 8.8 | 13.3% | Jun 13, 2023 | Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-3216 | HIGH | 8.8 | 0.9% | Jun 13, 2023 | Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-3215 | HIGH | 8.8 | 13.8% | Jun 13, 2023 | Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-3214 | HIGH | 8.8 | 0.9% | Jun 13, 2023 | Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially ex... |
| CVE-2023-34122 | — | — | — | Jun 13, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE... |
| CVE-2023-34121 | HIGH | 8.8 | 1.0% | Jun 13, 2023 | Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may all... |
| CVE-2023-34120 | HIGH | 7.8 | 0.1% | Jun 13, 2023 | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.... |
| CVE-2023-34113 | — | — | — | Jun 13, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE... |
| CVE-2023-28603 | HIGH | 7.1 | 0.2% | Jun 13, 2023 | Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may pote... |
| CVE-2023-28602 | HIGH | 7.7 | 0.3% | Jun 13, 2023 | Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A m... |
| CVE-2023-28601 | MEDIUM | 6.5 | 1.0% | Jun 13, 2023 | Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buf... |
| CVE-2023-28600 | MEDIUM | 5.4 | 0.2% | Jun 13, 2023 | Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to... |
| CVE-2023-1707 | HIGH | 7.5 | 0.9% | Jun 13, 2023 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure whe... |
| CVE-2023-34249 | CRITICAL | 9.8 | 0.6% | Jun 13, 2023 | benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is... |
| CVE-2023-34247 | MEDIUM | 4.1 | 0.4% | Jun 13, 2023 | Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package version... |
| CVE-2023-33620 | MEDIUM | 5.9 | 0.7% | Jun 13, 2023 | GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdro... |
| CVE-2023-31541 | CRITICAL | 9.8 | 1.8% | Jun 13, 2023 | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3... |
| CVE-2023-31439 | MEDIUM | 5.3 | 0.4% | Jun 13, 2023 | An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then... |
| CVE-2023-31438 | MEDIUM | 5.3 | 0.3% | Jun 13, 2023 | An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that... |
| CVE-2023-31437 | MEDIUM | 5.3 | 0.3% | Jun 13, 2023 | An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all exist... |
| CVE-2023-30179 | HIGH | 7.2 | 2.2% | Jun 13, 2023 | CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twi... |
| CVE-2023-28599 | MEDIUM | 4.3 | 0.7% | Jun 13, 2023 | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their d... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now