2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28935HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln...
CVE-2023-1712CRITICAL9.8Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack prior to 0.1.30.
CVE-2023-1699CRITICAL9.8Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an att...
CVE-2023-1014HIGH7.5Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account...
CVE-2023-1013MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Virames Vira-Investing al...
CVE-2023-26118MEDIUM5.3Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input...
CVE-2023-26117MEDIUM5.3Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resou...
CVE-2023-26116MEDIUM5.3Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angul...
CVE-2023-25000MEDIUM4.7HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-...
CVE-2023-0665MEDIUM6.5HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer met...
CVE-2023-0620MEDIUM6.7HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when config...
CVE-2023-28509HIGH7.5Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28508HIGH8.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28507CRITICAL9.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28506HIGH8.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28505HIGH8.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28504CRITICAL9.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28503CRITICAL9.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-28502CRITICAL9.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-1652HIGH7.1A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. ...
CVE-2023-0836HIGH7.5An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2...
CVE-2023-28501CRITICAL9.8Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu...
CVE-2023-22705MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions.
CVE-2023-1656HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server...
CVE-2023-0664HIGH7.8A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QE...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now