2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26109 | CRITICAL | 9.8 | 0.7% | Mar 9, 2023 | All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel m... |
| CVE-2023-26948 | HIGH | 7.5 | 0.6% | Mar 9, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/downloa... |
| CVE-2023-27974 | HIGH | 7.5 | 1.0% | Mar 9, 2023 | Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for a... |
| CVE-2023-0030 | HIGH | 7.8 | 0.2% | Mar 8, 2023 | A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that cause... |
| CVE-2023-24777 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. |
| CVE-2023-1283 | CRITICAL | 9.8 | 1.1% | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. |
| CVE-2023-27477 | MEDIUM | 4.3 | 0.6% | Mar 8, 2023 | wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_6... |
| CVE-2023-24782 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit... |
| CVE-2023-24282 | MEDIUM | 5.4 | 0.5% | Mar 8, 2023 | An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a cra... |
| CVE-2023-22892 | HIGH | 7.5 | 0.6% | Mar 8, 2023 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit... |
| CVE-2023-22891 | HIGH | 8.1 | 0.5% | Mar 8, 2023 | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited ... |
| CVE-2023-22890 | HIGH | 7.5 | 0.6% | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the l... |
| CVE-2023-22889 | CRITICAL | 9.8 | 1.3% | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re... |
| CVE-2023-26489 | CRITICAL | 9.9 | 1.3% | Mar 8, 2023 | wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a ... |
| CVE-2023-24533 | HIGH | 7.5 | 0.7% | Mar 8, 2023 | Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time t... |
| CVE-2023-24532 | MEDIUM | 5.3 | 0.8% | Mar 8, 2023 | The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific ... |
| CVE-2023-27486 | HIGH | 8.8 | 0.9% | Mar 8, 2023 | xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are confi... |
| CVE-2023-26956 | HIGH | 7.5 | 0.7% | Mar 8, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code. |
| CVE-2023-23760 | HIGH | 8.8 | 1.0% | Mar 8, 2023 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when buildi... |
| CVE-2023-1278 | MEDIUM | 6.1 | 0.5% | Mar 8, 2023 | A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some... |
| CVE-2023-1277 | HIGH | 7.8 | 1.8% | Mar 8, 2023 | A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. A... |
| CVE-2023-1276 | HIGH | 7.2 | 0.7% | Mar 8, 2023 | A vulnerability, which was classified as critical, has been found in SUL1SS_shop. This issue affects some unknown proces... |
| CVE-2023-27482 | CRITICAL | 10 | 72.0% | Mar 8, 2023 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for ... |
| CVE-2023-1275 | MEDIUM | 6.1 | 0.6% | Mar 8, 2023 | A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vuln... |
| CVE-2023-27088 | HIGH | 8.8 | 0.6% | Mar 8, 2023 | feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low per... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now