2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20864 | CRITICAL | 9.8 | 71.7% | Apr 20, 2023 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo... |
| CVE-2023-27090 | MEDIUM | 5.4 | 0.4% | Apr 20, 2023 | Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via ... |
| CVE-2023-30076 | CRITICAL | 9.8 | 0.8% | Apr 20, 2023 | Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.... |
| CVE-2023-23579 | HIGH | 7.8 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing ... |
| CVE-2023-22846 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s... |
| CVE-2023-22354 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe... |
| CVE-2023-22321 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci... |
| CVE-2023-22295 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall... |
| CVE-2023-30616 | MEDIUM | 6.5 | 0.3% | Apr 20, 2023 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-S... |
| CVE-2023-29528 | CRITICAL | 9 | 1.3% | Apr 20, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM... |
| CVE-2023-27495 | MEDIUM | 6.5 | 0.3% | Apr 20, 2023 | @fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enfor... |
| CVE-2023-23938 | MEDIUM | 4.8 | 0.5% | Apr 20, 2023 | Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are... |
| CVE-2023-1255 | MEDIUM | 5.9 | 1.0% | Apr 20, 2023 | Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it t... |
| CVE-2023-27351 | HIGH | 7.5 | 78.4% | Apr 20, 2023 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui... |
| CVE-2023-27350 | CRITICAL | 9.8 | 100.0% | Apr 20, 2023 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui... |
| CVE-2023-25601 | MEDIUM | 4.3 | 1.1% | Apr 20, 2023 | On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attac... |
| CVE-2023-29926 | CRITICAL | 9.8 | 1.2% | Apr 20, 2023 | PowerJob V4.3.2 has unauthorized interface that causes remote code execution. |
| CVE-2023-27652 | MEDIUM | 5.5 | 0.3% | Apr 20, 2023 | An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of serv... |
| CVE-2023-22309 | MEDIUM | 6.1 | 0.4% | Apr 20, 2023 | Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4. |
| CVE-2023-1767 | MEDIUM | 5.4 | 0.5% | Apr 20, 2023 | The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature o... |
| CVE-2023-2193 | CRITICAL | 9.1 | 0.6% | Apr 20, 2023 | Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker posse... |
| CVE-2023-2112 | HIGH | 7.8 | 0.2% | Apr 20, 2023 | Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. |
| CVE-2023-0384 | HIGH | 7.5 | 0.8% | Apr 20, 2023 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol... |
| CVE-2023-0383 | HIGH | 7.5 | 0.9% | Apr 20, 2023 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol... |
| CVE-2023-28047 | HIGH | 7.8 | 0.2% | Apr 20, 2023 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during inst... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now