2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25710MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1....
CVE-2023-25490MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plug...
CVE-2023-25479MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versi...
CVE-2023-22665MEDIUM5.4There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. ...
CVE-2023-28771CRITICAL9.8Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers...
CVE-2023-2007HIGH7.8The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when pe...
CVE-2023-30629HIGH7.5Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.1 through 0.3.7, the Vyper...
CVE-2023-30628HIGH8.8Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and p...
CVE-2023-30623HIGH8.8`embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.p...
CVE-2023-30414MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.
CVE-2023-30410MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /o...
CVE-2023-30408MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
CVE-2023-30406MEDIUM5.5Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property...
CVE-2023-30627MEDIUM5.4jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to versi...
CVE-2023-30626HIGH8.1Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory ...
CVE-2023-2260HIGH8.8Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVE-2023-2259HIGH7.2Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2...
CVE-2023-2258HIGH8.8Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVE-2023-2250MEDIUM6.7A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-...
CVE-2023-2019MEDIUM4.4A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from...
CVE-2023-2006HIGH7A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This is...
CVE-2023-29469MEDIUM6.5An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComp...
CVE-2023-28484MEDIUM6.5In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently...
CVE-2023-29530MEDIUM6.5Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22....
CVE-2023-2257HIGH7.8Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now