2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34570 | MEDIUM | 6.7 | 0.3% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/... |
| CVE-2023-34569 | MEDIUM | 6.7 | 0.3% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/Set... |
| CVE-2023-34568 | MEDIUM | 6.7 | 0.3% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/Pow... |
| CVE-2023-34567 | MEDIUM | 6.7 | 0.3% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/Set... |
| CVE-2023-34566 | CRITICAL | 9.8 | 0.9% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/sav... |
| CVE-2023-3163 | HIGH | 7.5 | 1.4% | Jun 8, 2023 | A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the functio... |
| CVE-2023-33443 | CRITICAL | 9.8 | 3.5% | Jun 8, 2023 | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attacke... |
| CVE-2023-33657 | HIGH | 7.5 | 1.0% | Jun 8, 2023 | A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_m... |
| CVE-2023-33660 | HIGH | 7.5 | 1.2% | Jun 8, 2023 | A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function... |
| CVE-2023-33658 | HIGH | 7.5 | 1.2% | Jun 8, 2023 | A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function... |
| CVE-2023-34969 | MEDIUM | 6.5 | 1.4% | Jun 8, 2023 | D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the... |
| CVE-2023-2986 | CRITICAL | 9.8 | 42.8% | Jun 8, 2023 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a... |
| CVE-2023-23482 | CRITICAL | 9.6 | 0.6% | Jun 8, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action ... |
| CVE-2023-23481 | MEDIUM | 5.4 | 0.4% | Jun 8, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerabi... |
| CVE-2023-23480 | MEDIUM | 5.4 | 0.4% | Jun 8, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2023-33847 | LOW | 3.1 | 0.6% | Jun 8, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the... |
| CVE-2023-33846 | MEDIUM | 5.4 | 0.5% | Jun 8, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to ... |
| CVE-2023-34239 | CRITICAL | 9.1 | 0.7% | Jun 8, 2023 | Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f... |
| CVE-2023-34238 | MEDIUM | 5.3 | 0.9% | Jun 8, 2023 | Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 conta... |
| CVE-2023-33849 | LOW | 3.7 | 0.4% | Jun 7, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit se... |
| CVE-2023-31200 | HIGH | 8 | 0.2% | Jun 7, 2023 | PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-sit... |
| CVE-2023-2904 | HIGH | 7.3 | 0.6% | Jun 7, 2023 | The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within we... |
| CVE-2023-29502 | MEDIUM | 4.3 | 0.5% | Jun 7, 2023 | Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.jso... |
| CVE-2023-29168 | HIGH | 7.5 | 0.5% | Jun 7, 2023 | The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.... |
| CVE-2023-29152 | HIGH | 8.1 | 0.4% | Jun 7, 2023 | By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vufo... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now