2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0208 | HIGH | 7.1 | 0.2% | Apr 1, 2023 | NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buf... |
| CVE-2023-1789 | CRITICAL | 9.8 | 0.3% | Apr 1, 2023 | Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. |
| CVE-2023-28845 | LOW | 3.5 | 0.4% | Mar 31, 2023 | Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly fi... |
| CVE-2023-28844 | MEDIUM | 6.5 | 0.6% | Mar 31, 2023 | Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to down... |
| CVE-2023-28645 | MEDIUM | 6.5 | 0.7% | Mar 31, 2023 | Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure... |
| CVE-2023-26485 | HIGH | 7.5 | 1.0% | Mar 31, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp... |
| CVE-2023-24824 | HIGH | 7.5 | 1.0% | Mar 31, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp... |
| CVE-2023-27163 | MEDIUM | 6.5 | 7.5% | Mar 31, 2023 | request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske... |
| CVE-2023-27162 | CRITICAL | 9.1 | 1.0% | Mar 31, 2023 | openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen... |
| CVE-2023-26858 | CRITICAL | 9.8 | 1.2% | Mar 31, 2023 | SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqs... |
| CVE-2023-1785 | CRITICAL | 9.8 | 0.7% | Mar 31, 2023 | A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Af... |
| CVE-2023-1784 | CRITICAL | 9.8 | 1.0% | Mar 31, 2023 | A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of ... |
| CVE-2023-29141 | CRITICAL | 9.8 | 1.2% | Mar 31, 2023 | An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An a... |
| CVE-2023-29140 | MEDIUM | 5.3 | 0.4% | Mar 31, 2023 | An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see ... |
| CVE-2023-29139 | MEDIUM | 6.5 | 0.6% | Mar 31, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissio... |
| CVE-2023-29137 | MEDIUM | 4.3 | 0.4% | Mar 31, 2023 | An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for Growt... |
| CVE-2023-27160 | HIGH | 7.2 | 1.2% | Mar 31, 2023 | forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}.... |
| CVE-2023-27159 | HIGH | 7.5 | 36.2% | Mar 31, 2023 | Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic... |
| CVE-2023-26925 | HIGH | 7.5 | 0.9% | Mar 31, 2023 | An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted n... |
| CVE-2023-23594 | CRITICAL | 9.8 | 1.5% | Mar 31, 2023 | An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-... |
| CVE-2023-28843 | CRITICAL | 9.8 | 1.2% | Mar 31, 2023 | PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment suppo... |
| CVE-2023-28879 | CRITICAL | 9.8 | 6.3% | Mar 31, 2023 | In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to t... |
| CVE-2023-28877 | HIGH | 7.5 | 0.5% | Mar 31, 2023 | The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration dat... |
| CVE-2023-28862 | CRITICAL | 9.8 | 1.0% | Mar 31, 2023 | An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrec... |
| CVE-2023-28464 | HIGH | 7.8 | 0.3% | Mar 31, 2023 | hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_con... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now