2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29196MEDIUM6.1Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst...
CVE-2023-29002MEDIUM6.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Ciliu...
CVE-2023-28004CRITICAL9.8 A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul...
CVE-2023-29413HIGH7.5 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when ac...
CVE-2023-29412CRITICAL9.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2023-29411CRITICAL9.8 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative...
CVE-2023-28856MEDIUM6.5Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` comman...
CVE-2023-28839CRITICAL9.8Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed f...
CVE-2023-28440LOW2.7Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a...
CVE-2023-28003HIGH8.8 A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized...
CVE-2023-26049MEDIUM5.3Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl...
CVE-2023-26048MEDIUM5.3Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotate...
CVE-2023-25555HIGH8.1 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln...
CVE-2023-25554HIGH7.8 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability ...
CVE-2023-25553MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit...
CVE-2023-25552HIGH8.1 A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or de...
CVE-2023-25551MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability ...
CVE-2023-25550CRITICAL9.8 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote cod...
CVE-2023-25549CRITICAL9.8 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote c...
CVE-2023-25548MEDIUM6.5 A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE e...
CVE-2023-25547HIGH8.8 A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install pa...
CVE-2023-29887HIGH7.5A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitra...
CVE-2023-22003LOW3.3Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte...
CVE-2023-22002MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-22001MEDIUM4.6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now