2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26288MEDIUM5.5IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated use...
CVE-2023-48396CRITICAL9.1Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can...
CVE-2023-52888MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Only free buffer VA that i...
CVE-2023-42959HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able ...
CVE-2023-42958HIGH7.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.4. An app may be...
CVE-2023-42957LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom...
CVE-2023-42949LOW3.3This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, wa...
CVE-2023-42948LOW3.3This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may...
CVE-2023-42943MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma ...
CVE-2023-42925LOW3.3The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17,...
CVE-2023-42918MEDIUM6.3A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed proc...
CVE-2023-40398HIGH8.8This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS...
CVE-2023-40396HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, wat...
CVE-2023-52887MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightl...
CVE-2023-50700HIGH7.8Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be call...
CVE-2023-38522HIGH7.5Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to or...
CVE-2023-49921MEDIUM6.5An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This...
CVE-2023-7271MEDIUM5.5Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect a...
CVE-2023-45249CRITICAL9.8Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct...
CVE-2023-48362HIGH8.8XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file ...
CVE-2023-32471MEDIUM6Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated mali...
CVE-2023-32466MEDIUM5.7Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal...
CVE-2023-7269HIGH7.5The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation...
CVE-2023-7268MEDIUM6.5The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, a...
CVE-2023-40704CRITICAL9.8The product does not require unique and complex passwords to be created during installation. Using Philips's default pa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now