2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1180MEDIUM6.1A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as pr...
CVE-2023-1179MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory Sys...
CVE-2023-1175MEDIUM6.6Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
CVE-2023-26481MEDIUM6.5authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created...
CVE-2023-25819MEDIUM5.3Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T...
CVE-2023-26490HIGH8.8mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - wh...
CVE-2023-26487MEDIUM6.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2023-26486MEDIUM6.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2023-23929HIGH8.8vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t...
CVE-2023-27290CRITICAL9.1Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 24...
CVE-2023-26779CRITICAL9.8CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
CVE-2023-26491MEDIUM6.1RSSHub is an open source and extensible RSS feed generator. When the URL parameters contain certain special characters, ...
CVE-2023-26483MEDIUM5.3gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication suppo...
CVE-2023-26047MEDIUM6.1teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-w...
CVE-2023-25403HIGH7.5CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored...
CVE-2023-25402HIGH7.5CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, ...
CVE-2023-1170MEDIUM6.6Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
CVE-2023-27574CRITICAL9.8ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENT...
CVE-2023-27567HIGH7.5In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
CVE-2023-26492HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side R...
CVE-2023-26488MEDIUM6.5OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for m...
CVE-2023-26213HIGH7.2On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injectio...
CVE-2023-23927MEDIUM5.4Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an...
CVE-2023-23313MEDIUM6.1Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi scrip...
CVE-2023-0968MEDIUM6.1The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now