2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24205 | CRITICAL | 9.8 | 1.3% | Feb 23, 2023 | Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via ... |
| CVE-2023-0755 | CRITICAL | 9.8 | 11.8% | Feb 23, 2023 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash t... |
| CVE-2023-0754 | CRITICAL | 9.8 | 2.9% | Feb 23, 2023 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the ... |
| CVE-2023-26326 | CRITICAL | 9.8 | 3.8% | Feb 23, 2023 | The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization... |
| CVE-2023-26325 | HIGH | 8.8 | 0.9% | Feb 23, 2023 | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerabili... |
| CVE-2023-24317 | HIGH | 8.1 | 1.7% | Feb 23, 2023 | Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_or... |
| CVE-2023-23920 | MEDIUM | 4.2 | 0.5% | Feb 23, 2023 | An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an ... |
| CVE-2023-23919 | HIGH | 7.5 | 2.2% | Feb 23, 2023 | A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not cl... |
| CVE-2023-23918 | HIGH | 7.5 | 2.0% | Feb 23, 2023 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to... |
| CVE-2023-23917 | HIGH | 8.8 | 1.0% | Feb 23, 2023 | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the ... |
| CVE-2023-23916 | MEDIUM | 6.5 | 1.7% | Feb 23, 2023 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTT... |
| CVE-2023-23915 | MEDIUM | 6.5 | 0.9% | Feb 23, 2023 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional... |
| CVE-2023-23914 | CRITICAL | 9.1 | 0.9% | Feb 23, 2023 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional... |
| CVE-2023-20089 | MEDIUM | 6.5 | 0.3% | Feb 23, 2023 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Appli... |
| CVE-2023-20050 | HIGH | 7.8 | 0.3% | Feb 23, 2023 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com... |
| CVE-2023-20016 | MEDIUM | 6.5 | 0.1% | Feb 23, 2023 | A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export featur... |
| CVE-2023-20015 | MEDIUM | 6.7 | 0.2% | Feb 23, 2023 | A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200,... |
| CVE-2023-20012 | MEDIUM | 4.6 | 0.3% | Feb 23, 2023 | A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used i... |
| CVE-2023-20011 | HIGH | 8.8 | 0.4% | Feb 23, 2023 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and C... |
| CVE-2023-0597 | MEDIUM | 5.5 | 0.3% | Feb 23, 2023 | A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the ... |
| CVE-2023-0044 | MEDIUM | 6.1 | 0.5% | Feb 23, 2023 | If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated... |
| CVE-2023-22476 | MEDIUM | 4.3 | 0.6% | Feb 23, 2023 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-l... |
| CVE-2023-24415 | HIGH | 8.8 | 0.3% | Feb 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. |
| CVE-2023-24104 | CRITICAL | 9.8 | 0.8% | Feb 23, 2023 | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets. |
| CVE-2023-0988 | HIGH | 8.8 | 0.5% | Feb 23, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now