2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22380MEDIUM6.5A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when build...
CVE-2023-0866HIGH7.8Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV.
CVE-2023-25653HIGH7.5node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-b...
CVE-2023-25602HIGH7.8A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb vers...
CVE-2023-23784MEDIUM6.5A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, Forti...
CVE-2023-23783HIGH7.8A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions...
CVE-2023-23782HIGH7.8A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, Fo...
CVE-2023-23781HIGH8.8A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3...
CVE-2023-23780HIGH8.8A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through ...
CVE-2023-23779HIGH8.8Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
CVE-2023-23778MEDIUM6.5A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions...
CVE-2023-22638MEDIUM5.4Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below...
CVE-2023-0475MEDIUM6.5HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
CVE-2023-24807HIGH7.5Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods ar...
CVE-2023-24485HIGH7.8Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM o...
CVE-2023-24484MEDIUM5.5A malicious user can cause log files to be written to a directory that they do not have permission to write to.
CVE-2023-24483HIGH7.8A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to ...
CVE-2023-23947HIGH8.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 a...
CVE-2023-23936MEDIUM5.4Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library do...
CVE-2023-23752MEDIUM5.3An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservic...
CVE-2023-23926HIGH8.1APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in ...
CVE-2023-23558MEDIUM6.3In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sen...
CVE-2023-25173HIGH7.8containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where ...
CVE-2023-25153MEDIUM5.5containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there wa...
CVE-2023-24238CRITICAL9.8TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city paramet...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now