2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36258 | CRITICAL | 9.8 | 1.0% | Jul 3, 2023 | An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex... |
| CVE-2023-36817 | CRITICAL | 9.1 | 0.5% | Jul 3, 2023 | `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f... |
| CVE-2023-26258 | CRITICAL | 9.8 | 34.2% | Jul 3, 2023 | Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe... |
| CVE-2023-35797 | CRITICAL | 9.8 | 2.1% | Jul 3, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A... |
| CVE-2023-26136 | CRITICAL | 9.8 | 2.1% | Jul 1, 2023 | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cook... |
| CVE-2023-31997 | CRITICAL | 9 | 0.2% | Jul 1, 2023 | UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to acc... |
| CVE-2023-28365 | CRITICAL | 9.1 | 0.6% | Jul 1, 2023 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems ... |
| CVE-2023-28324 | CRITICAL | 9.8 | 11.8% | Jul 1, 2023 | A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es... |
| CVE-2023-28323 | CRITICAL | 9.8 | 3.1% | Jul 1, 2023 | A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to... |
| CVE-2023-22814 | CRITICAL | 9.8 | 0.6% | Jul 1, 2023 | An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow ... |
| CVE-2023-36812 | CRITICAL | 9.8 | 14.3% | Jun 30, 2023 | OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Exec... |
| CVE-2023-3490 | CRITICAL | 9.8 | 0.8% | Jun 30, 2023 | SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. |
| CVE-2023-31543 | CRITICAL | 9.8 | 1.1% | Jun 30, 2023 | A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted P... |
| CVE-2023-37303 | CRITICAL | 9.8 | 0.8% | Jun 30, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to bl... |
| CVE-2023-35175 | CRITICAL | 9.8 | 1.8% | Jun 30, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of... |
| CVE-2023-3473 | CRITICAL | 9.8 | 0.7% | Jun 30, 2023 | A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is ... |
| CVE-2023-2846 | CRITICAL | 9.1 | 0.9% | Jun 30, 2023 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules... |
| CVE-2023-26135 | CRITICAL | 9.8 | 0.7% | Jun 30, 2023 | All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.... |
| CVE-2023-3249 | CRITICAL | 9.8 | 0.9% | Jun 30, 2023 | The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in version... |
| CVE-2023-2834 | CRITICAL | 9.8 | 1.9% | Jun 30, 2023 | The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is ... |
| CVE-2023-33190 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior... |
| CVE-2023-36487 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take ov... |
| CVE-2023-35830 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.0... |
| CVE-2023-26616 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in Set... |
| CVE-2023-26613 | CRITICAL | 9.8 | 29.1% | Jun 29, 2023 | An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now