2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32710MEDIUM5.3In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100,...
CVE-2023-32709MEDIUM4.3In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a ...
CVE-2023-32708HIGH8.8In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a ...
CVE-2023-32707HIGH8.8In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, ...
CVE-2023-32706MEDIUM6.5On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted me...
CVE-2023-32690HIGH7.5libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following...
CVE-2023-32324MEDIUM5.5OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability w...
CVE-2023-33963CRITICAL9.8DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerabilit...
CVE-2023-32310HIGH8.1DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and del...
CVE-2023-28066HIGH7.8 Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local auth...
CVE-2023-28043MEDIUM6.5 Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privile...
CVE-2023-33965HIGH8.8Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. ...
CVE-2023-33552HIGH7.8Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execut...
CVE-2023-33551HIGH7.8Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to...
CVE-2023-3035MEDIUM5.4A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Af...
CVE-2023-33546MEDIUM5.5Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parame...
CVE-2023-33544MEDIUM5.5hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high...
CVE-2023-22648HIGH8.8A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected ...
CVE-2023-22647HIGH8An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permiss...
CVE-2023-32181MEDIUM6.5A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for D...
CVE-2023-22652MEDIUM6.5A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS...
CVE-2023-3029HIGH8.8A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Th...
CVE-2023-3028CRITICAL9.8Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry ...
CVE-2023-24584CRITICAL9.8 Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. Thi...
CVE-2023-33778CRITICAL9.8Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmwa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now