2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27566HIGH7.8Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info T...
CVE-2023-27561HIGH7runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linu...
CVE-2023-24643CRITICAL9.8Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms...
CVE-2023-24642CRITICAL9.8Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms...
CVE-2023-24641CRITICAL9.8Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms...
CVE-2023-26604HIGH7.8systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible su...
CVE-2023-20104MEDIUM6.1A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attac...
CVE-2023-20088HIGH7.5A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse co...
CVE-2023-20079HIGH7.5Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated...
CVE-2023-20078CRITICAL9.8Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated...
CVE-2023-20069MEDIUM5.4A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo...
CVE-2023-20062MEDIUM4.3Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s...
CVE-2023-20061MEDIUM6.5Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s...
CVE-2023-1165HIGH7.2A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown pa...
CVE-2023-0957CRITICAL9.6An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW...
CVE-2023-1164HIGH7.8A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is...
CVE-2023-1163MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as c...
CVE-2023-1162HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1...
CVE-2023-0578MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T...
CVE-2023-0577MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T...
CVE-2023-27560HIGH7.5Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
CVE-2023-0457HIGH7.5Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series,...
CVE-2023-1160MEDIUM5.5Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
CVE-2023-1101HIGH8.8SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use exce...
CVE-2023-0656HIGH7.5A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now