2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27566 | HIGH | 7.8 | 0.6% | Mar 3, 2023 | Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info T... |
| CVE-2023-27561 | HIGH | 7 | 0.4% | Mar 3, 2023 | runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linu... |
| CVE-2023-24643 | CRITICAL | 9.8 | 0.8% | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms... |
| CVE-2023-24642 | CRITICAL | 9.8 | 0.8% | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms... |
| CVE-2023-24641 | CRITICAL | 9.8 | 0.8% | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms... |
| CVE-2023-26604 | HIGH | 7.8 | 1.1% | Mar 3, 2023 | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible su... |
| CVE-2023-20104 | MEDIUM | 6.1 | 0.5% | Mar 3, 2023 | A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attac... |
| CVE-2023-20088 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse co... |
| CVE-2023-20079 | HIGH | 7.5 | 10.3% | Mar 3, 2023 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated... |
| CVE-2023-20078 | CRITICAL | 9.8 | 10.4% | Mar 3, 2023 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated... |
| CVE-2023-20069 | MEDIUM | 5.4 | 0.4% | Mar 3, 2023 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo... |
| CVE-2023-20062 | MEDIUM | 4.3 | 0.5% | Mar 3, 2023 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s... |
| CVE-2023-20061 | MEDIUM | 6.5 | 0.7% | Mar 3, 2023 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s... |
| CVE-2023-1165 | HIGH | 7.2 | 0.8% | Mar 3, 2023 | A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown pa... |
| CVE-2023-0957 | CRITICAL | 9.6 | 0.4% | Mar 3, 2023 | An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW... |
| CVE-2023-1164 | HIGH | 7.8 | 0.4% | Mar 3, 2023 | A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is... |
| CVE-2023-1163 | MEDIUM | 6.5 | 1.8% | Mar 3, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as c... |
| CVE-2023-1162 | HIGH | 8.8 | 26.0% | Mar 3, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1... |
| CVE-2023-0578 | MEDIUM | 6.1 | 0.4% | Mar 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T... |
| CVE-2023-0577 | MEDIUM | 6.1 | 0.4% | Mar 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information T... |
| CVE-2023-27560 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields. |
| CVE-2023-0457 | HIGH | 7.5 | 1.2% | Mar 3, 2023 | Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series,... |
| CVE-2023-1160 | MEDIUM | 5.5 | 0.3% | Mar 3, 2023 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. |
| CVE-2023-1101 | HIGH | 8.8 | 0.7% | Mar 2, 2023 | SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use exce... |
| CVE-2023-0656 | HIGH | 7.5 | 41.3% | Mar 2, 2023 | A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now