2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20860HIGH7.5Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuratio...
CVE-2023-1665CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
CVE-2023-1648Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-0326. Reason: This candidate is a duplicate of C...
CVE-2023-1637MEDIUM5.5A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 ...
CVE-2023-0326MEDIUM4.3An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where...
CVE-2023-0210HIGH7.5A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based sys...
CVE-2023-0179HIGH7.8A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the lea...
CVE-2023-28640LOW3.1Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an au...
CVE-2023-28638MEDIUM5.9Snappier is a high performance C# implementation of the Snappy compression algorithm. This is a buffer overrun vulnerabi...
CVE-2023-28630MEDIUM4.4GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environm...
CVE-2023-28629MEDIUM5.4GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerabil...
CVE-2023-28628MEDIUM6.1lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an ...
CVE-2023-28627HIGH8.8pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web...
CVE-2023-28597HIGH7.5Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local ...
CVE-2023-28596HIGH7.8Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A lo...
CVE-2023-25908HIGH7.8Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability th...
CVE-2023-25878MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25877MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25876MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25875MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25874HIGH7.8Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2023-25873HIGH7.8Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-25872HIGH7.8Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2023-25871HIGH7.8Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Use After Free vulnerability that could result ...
CVE-2023-25870HIGH7.8Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds write vulnerability that could r...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now