2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0208HIGH7.1 NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buf...
CVE-2023-1789CRITICAL9.8Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.
CVE-2023-28845LOW3.5Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly fi...
CVE-2023-28844MEDIUM6.5Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to down...
CVE-2023-28645MEDIUM6.5Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure...
CVE-2023-26485HIGH7.5cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp...
CVE-2023-24824HIGH7.5cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp...
CVE-2023-27163MEDIUM6.5request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske...
CVE-2023-27162CRITICAL9.1openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen...
CVE-2023-26858CRITICAL9.8SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqs...
CVE-2023-1785CRITICAL9.8A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Af...
CVE-2023-1784CRITICAL9.8A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of ...
CVE-2023-29141CRITICAL9.8An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An a...
CVE-2023-29140MEDIUM5.3An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see ...
CVE-2023-29139MEDIUM6.5An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissio...
CVE-2023-29137MEDIUM4.3An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for Growt...
CVE-2023-27160HIGH7.2forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}....
CVE-2023-27159HIGH7.5Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic...
CVE-2023-26925HIGH7.5An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted n...
CVE-2023-23594CRITICAL9.8An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-...
CVE-2023-28843CRITICAL9.8PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment suppo...
CVE-2023-28879CRITICAL9.8In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to t...
CVE-2023-28877HIGH7.5The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration dat...
CVE-2023-28862CRITICAL9.8An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrec...
CVE-2023-28464HIGH7.8hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_con...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now