2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29196 | MEDIUM | 6.1 | 0.3% | Apr 18, 2023 | Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst... |
| CVE-2023-29002 | MEDIUM | 6.3 | 0.2% | Apr 18, 2023 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Ciliu... |
| CVE-2023-28004 | CRITICAL | 9.8 | 1.1% | Apr 18, 2023 | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul... |
| CVE-2023-29413 | HIGH | 7.5 | 0.7% | Apr 18, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when ac... |
| CVE-2023-29412 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2023-29411 | CRITICAL | 9.8 | 1.3% | Apr 18, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative... |
| CVE-2023-28856 | MEDIUM | 6.5 | 1.0% | Apr 18, 2023 | Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` comman... |
| CVE-2023-28839 | CRITICAL | 9.8 | 0.8% | Apr 18, 2023 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed f... |
| CVE-2023-28440 | LOW | 2.7 | 0.7% | Apr 18, 2023 | Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a... |
| CVE-2023-28003 | HIGH | 8.8 | 0.3% | Apr 18, 2023 | A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized... |
| CVE-2023-26049 | MEDIUM | 5.3 | 1.3% | Apr 18, 2023 | Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl... |
| CVE-2023-26048 | MEDIUM | 5.3 | 3.3% | Apr 18, 2023 | Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotate... |
| CVE-2023-25555 | HIGH | 8.1 | 0.9% | Apr 18, 2023 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln... |
| CVE-2023-25554 | HIGH | 7.8 | 0.6% | Apr 18, 2023 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability ... |
| CVE-2023-25553 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit... |
| CVE-2023-25552 | HIGH | 8.1 | 0.5% | Apr 18, 2023 | A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or de... |
| CVE-2023-25551 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability ... |
| CVE-2023-25550 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote cod... |
| CVE-2023-25549 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote c... |
| CVE-2023-25548 | MEDIUM | 6.5 | 0.5% | Apr 18, 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE e... |
| CVE-2023-25547 | HIGH | 8.8 | 0.9% | Apr 18, 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install pa... |
| CVE-2023-29887 | HIGH | 7.5 | 4.7% | Apr 18, 2023 | A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitra... |
| CVE-2023-22003 | LOW | 3.3 | 0.2% | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte... |
| CVE-2023-22002 | MEDIUM | 6 | 0.3% | Apr 18, 2023 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2023-22001 | MEDIUM | 4.6 | 0.3% | Apr 18, 2023 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now