2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34312 | HIGH | 7.8 | 0.6% | Jun 1, 2023 | In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate poi... |
| CVE-2023-33719 | MEDIUM | 5.5 | 0.3% | Jun 1, 2023 | mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp |
| CVE-2023-33716 | MEDIUM | 5.5 | 0.2% | Jun 1, 2023 | mp4v2 v2.1.3 was discovered to contain a memory leak via the class MP4StringProperty at mp4property.cpp. |
| CVE-2023-33461 | MEDIUM | 5.5 | 0.4% | Jun 1, 2023 | iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for fu... |
| CVE-2023-29748 | HIGH | 7.5 | 1.2% | Jun 1, 2023 | Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modif... |
| CVE-2023-30758 | MEDIUM | 5.4 | 0.7% | Jun 1, 2023 | Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and earlier allows a remote authenticated attacker to inject a... |
| CVE-2023-29159 | HIGH | 7.5 | 2.0% | Jun 1, 2023 | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthentic... |
| CVE-2023-29154 | HIGH | 7.2 | 44.0% | Jun 1, 2023 | SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the ... |
| CVE-2023-28937 | HIGH | 8.8 | 0.8% | Jun 1, 2023 | DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration... |
| CVE-2023-28824 | MEDIUM | 4.9 | 0.6% | Jun 1, 2023 | Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can a... |
| CVE-2023-28713 | HIGH | 8.1 | 0.4% | Jun 1, 2023 | Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account informatio... |
| CVE-2023-28657 | HIGH | 8.8 | 0.7% | Jun 1, 2023 | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC whe... |
| CVE-2023-28651 | MEDIUM | 4.8 | 64.8% | Jun 1, 2023 | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can acces... |
| CVE-2023-28399 | HIGH | 7.8 | 0.2% | Jun 1, 2023 | Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL ... |
| CVE-2023-3026 | MEDIUM | 6.1 | 0.5% | Jun 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. |
| CVE-2023-2985 | MEDIUM | 5.5 | 0.2% | Jun 1, 2023 | A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a ... |
| CVE-2023-2977 | HIGH | 7.1 | 0.3% | Jun 1, 2023 | A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verify... |
| CVE-2023-2598 | HIGH | 7.8 | 1.4% | Jun 1, 2023 | A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the L... |
| CVE-2023-23955 | HIGH | 8.1 | 0.5% | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request F... |
| CVE-2023-23954 | MEDIUM | 5.4 | 0.3% | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scr... |
| CVE-2023-23953 | HIGH | 7.8 | 0.2% | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privile... |
| CVE-2023-23952 | CRITICAL | 9.8 | 1.4% | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vul... |
| CVE-2023-33643 | HIGH | 7.2 | 0.9% | May 31, 2023 | H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at... |
| CVE-2023-33642 | HIGH | 7.2 | 0.9% | May 31, 2023 | H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at... |
| CVE-2023-33641 | HIGH | 7.2 | 0.9% | May 31, 2023 | H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddMacList interface at /go... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now