2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1180 | MEDIUM | 6.1 | 0.6% | Mar 5, 2023 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as pr... |
| CVE-2023-1179 | MEDIUM | 5.4 | 0.6% | Mar 5, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory Sys... |
| CVE-2023-1175 | MEDIUM | 6.6 | 0.4% | Mar 4, 2023 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. |
| CVE-2023-26481 | MEDIUM | 6.5 | 0.3% | Mar 4, 2023 | authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created... |
| CVE-2023-25819 | MEDIUM | 5.3 | 0.5% | Mar 4, 2023 | Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T... |
| CVE-2023-26490 | HIGH | 8.8 | 2.2% | Mar 4, 2023 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - wh... |
| CVE-2023-26487 | MEDIUM | 6.1 | 0.8% | Mar 4, 2023 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2023-26486 | MEDIUM | 6.1 | 0.8% | Mar 4, 2023 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2023-23929 | HIGH | 8.8 | 0.6% | Mar 4, 2023 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t... |
| CVE-2023-27290 | CRITICAL | 9.1 | 8.6% | Mar 3, 2023 | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 24... |
| CVE-2023-26779 | CRITICAL | 9.8 | 1.4% | Mar 3, 2023 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). |
| CVE-2023-26491 | MEDIUM | 6.1 | 0.4% | Mar 3, 2023 | RSSHub is an open source and extensible RSS feed generator. When the URL parameters contain certain special characters, ... |
| CVE-2023-26483 | MEDIUM | 5.3 | 1.0% | Mar 3, 2023 | gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication suppo... |
| CVE-2023-26047 | MEDIUM | 6.1 | 0.5% | Mar 3, 2023 | teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-w... |
| CVE-2023-25403 | HIGH | 7.5 | 0.7% | Mar 3, 2023 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored... |
| CVE-2023-25402 | HIGH | 7.5 | 0.6% | Mar 3, 2023 | CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, ... |
| CVE-2023-1170 | MEDIUM | 6.6 | 0.5% | Mar 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. |
| CVE-2023-27574 | CRITICAL | 9.8 | 0.4% | Mar 3, 2023 | ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENT... |
| CVE-2023-27567 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel. |
| CVE-2023-26492 | HIGH | 7.5 | 1.0% | Mar 3, 2023 | Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side R... |
| CVE-2023-26488 | MEDIUM | 6.5 | 0.7% | Mar 3, 2023 | OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for m... |
| CVE-2023-26213 | HIGH | 7.2 | 7.9% | Mar 3, 2023 | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injectio... |
| CVE-2023-23927 | MEDIUM | 5.4 | 0.8% | Mar 3, 2023 | Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an... |
| CVE-2023-23313 | MEDIUM | 6.1 | 0.4% | Mar 3, 2023 | Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi scrip... |
| CVE-2023-0968 | MEDIUM | 6.1 | 1.3% | Mar 3, 2023 | The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now