2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26109CRITICAL9.8All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel m...
CVE-2023-26948HIGH7.5onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/downloa...
CVE-2023-27974HIGH7.5Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for a...
CVE-2023-0030HIGH7.8A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that cause...
CVE-2023-24777CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
CVE-2023-1283CRITICAL9.8Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
CVE-2023-27477MEDIUM4.3wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_6...
CVE-2023-24782CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit...
CVE-2023-24282MEDIUM5.4An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a cra...
CVE-2023-22892HIGH7.5There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit...
CVE-2023-22891HIGH8.1There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited ...
CVE-2023-22890HIGH7.5SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the l...
CVE-2023-22889CRITICAL9.8SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re...
CVE-2023-26489CRITICAL9.9wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a ...
CVE-2023-24533HIGH7.5Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time t...
CVE-2023-24532MEDIUM5.3The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific ...
CVE-2023-27486HIGH8.8xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are confi...
CVE-2023-26956HIGH7.5onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
CVE-2023-23760HIGH8.8A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when buildi...
CVE-2023-1278MEDIUM6.1A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some...
CVE-2023-1277HIGH7.8A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. A...
CVE-2023-1276HIGH7.2A vulnerability, which was classified as critical, has been found in SUL1SS_shop. This issue affects some unknown proces...
CVE-2023-27482CRITICAL10homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for ...
CVE-2023-1275MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vuln...
CVE-2023-27088HIGH8.8feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low per...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now