2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30637 | HIGH | 7.5 | 0.7% | Apr 13, 2023 | Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installati... |
| CVE-2023-30636 | HIGH | 7.5 | 1.0% | Apr 13, 2023 | TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader... |
| CVE-2023-30635 | HIGH | 7.5 | 1.0% | Apr 13, 2023 | TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from th... |
| CVE-2023-1326 | HIGH | 7.8 | 0.9% | Apr 13, 2023 | A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system... |
| CVE-2023-29573 | MEDIUM | 5.5 | 0.3% | Apr 13, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. |
| CVE-2023-27748 | CRITICAL | 9.8 | 0.7% | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attac... |
| CVE-2023-27747 | HIGH | 7.5 | 1.1% | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows at... |
| CVE-2023-27746 | CRITICAL | 9.8 | 1.8% | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke... |
| CVE-2023-27667 | CRITICAL | 9.8 | 0.7% | Apr 13, 2023 | Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-26416 | HIGH | 7.8 | 0.4% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that ... |
| CVE-2023-26415 | HIGH | 7.8 | 0.3% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could ... |
| CVE-2023-26414 | HIGH | 7.8 | 0.4% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result... |
| CVE-2023-26413 | HIGH | 7.8 | 0.4% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that ... |
| CVE-2023-26412 | HIGH | 7.8 | 0.4% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that... |
| CVE-2023-26411 | HIGH | 7.8 | 0.3% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing... |
| CVE-2023-26410 | HIGH | 7.8 | 0.4% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result... |
| CVE-2023-26409 | HIGH | 7.8 | 0.3% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing... |
| CVE-2023-26398 | HIGH | 7.8 | 0.3% | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing... |
| CVE-2023-24509 | HIGH | 7.8 | 0.2% | Apr 13, 2023 | On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundan... |
| CVE-2023-22951 | HIGH | 8.8 | 0.8% | Apr 13, 2023 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal syste... |
| CVE-2023-20866 | MEDIUM | 6.5 | 0.7% | Apr 13, 2023 | In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes ... |
| CVE-2023-20863 | MEDIUM | 6.5 | 1.1% | Apr 13, 2023 | In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a speci... |
| CVE-2023-1271 | — | — | — | Apr 13, 2023 | Rejected reason: Duplicate. Please use CVE-2023-24421. |
| CVE-2023-29084 | HIGH | 7.2 | 98.4% | Apr 13, 2023 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti... |
| CVE-2023-26264 | MEDIUM | 5.5 | 0.2% | Apr 13, 2023 | All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now