2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31756MEDIUM6.7A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firm...
CVE-2023-26818MEDIUM5.5Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT...
CVE-2023-2806HIGH8.8A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the ...
CVE-2023-28045HIGH7.1 Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with l...
CVE-2023-33240HIGH7.8Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53...
CVE-2023-1618HIGH8.6Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 ***...
CVE-2023-2704CRITICAL9.8The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5....
CVE-2023-32680CRITICAL9.6Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be i...
CVE-2023-30470CRITICAL9.8A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior...
CVE-2023-28753CRITICAL9.8netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could ...
CVE-2023-28081CRITICAL9.8A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an...
CVE-2023-25933CRITICAL9.8A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a ma...
CVE-2023-24833HIGH7.5A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could ha...
CVE-2023-24832HIGH7.5A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used b...
CVE-2023-23759HIGH7.5There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. Th...
CVE-2023-23557CRITICAL9.8An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad co...
CVE-2023-23556CRITICAL9.8An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have be...
CVE-2023-1195MEDIUM5.5A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue o...
CVE-2023-2025MEDIUM6.5OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorize...
CVE-2023-2024HIGH7.5Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unau...
CVE-2023-31655HIGH7.5redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial ...
CVE-2023-29720MEDIUM6.1SofaWiki <=3.8.9 is vulnerable to Cross Site Scripting (XSS) via index.php.
CVE-2023-32100HIGH7.5 Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earli...
CVE-2023-32099HIGH7.5 Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier r...
CVE-2023-32098HIGH7.5 Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and e...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now