2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29932 | MEDIUM | 5.5 | 0.2% | May 5, 2023 | llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOp... |
| CVE-2023-22874 | MEDIUM | 5.5 | 0.2% | May 5, 2023 | IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration fi... |
| CVE-2023-30243 | HIGH | 7.5 | 0.6% | May 5, 2023 | Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access t... |
| CVE-2023-30013 | CRITICAL | 9.8 | 25.9% | May 5, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s... |
| CVE-2023-30242 | CRITICAL | 9.8 | 0.7% | May 5, 2023 | NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. |
| CVE-2023-2540 | — | — | — | May 5, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-2539 | — | — | — | May 5, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-2537 | — | — | — | May 5, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-2536 | — | — | — | May 5, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-2535 | — | — | — | May 5, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-28068 | HIGH | 7.8 | 0.2% | May 5, 2023 | Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authentica... |
| CVE-2023-32235 | HIGH | 7.5 | 39.1% | May 5, 2023 | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2... |
| CVE-2023-30090 | CRITICAL | 9.8 | 0.8% | May 5, 2023 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. T... |
| CVE-2023-30135 | CRITICAL | 9.8 | 2.4% | May 5, 2023 | Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName paramet... |
| CVE-2023-30122 | CRITICAL | 9.8 | 1.0% | May 5, 2023 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System ... |
| CVE-2023-2531 | CRITICAL | 9.8 | 0.8% | May 5, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3. |
| CVE-2023-1894 | MEDIUM | 5.3 | 0.4% | May 4, 2023 | A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An is... |
| CVE-2023-30282 | HIGH | 7.5 | 0.6% | May 4, 2023 | PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, ... |
| CVE-2023-30093 | MEDIUM | 6.1 | 0.5% | May 4, 2023 | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attac... |
| CVE-2023-31415 | HIGH | 8.8 | 1.0% | May 4, 2023 | Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics... |
| CVE-2023-31414 | HIGH | 8.8 | 0.6% | May 4, 2023 | Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana ya... |
| CVE-2023-31413 | LOW | 3.3 | 0.2% | May 4, 2023 | Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or P... |
| CVE-2023-30399 | HIGH | 8.1 | 0.9% | May 4, 2023 | Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to ... |
| CVE-2023-30328 | CRITICAL | 9.8 | 1.1% | May 4, 2023 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authenticati... |
| CVE-2023-30216 | MEDIUM | 5.4 | 0.3% | May 4, 2023 | Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain use... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now