2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0801 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and too... |
| CVE-2023-0800 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-s... |
| CVE-2023-0799 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-se... |
| CVE-2023-0798 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-se... |
| CVE-2023-0797 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tool... |
| CVE-2023-0796 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-se... |
| CVE-2023-0795 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-se... |
| CVE-2023-0518 | HIGH | 7.5 | 1.2% | Feb 13, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions start... |
| CVE-2023-0819 | HIGH | 7.8 | 0.4% | Feb 13, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV. |
| CVE-2023-0818 | MEDIUM | 5.5 | 0.4% | Feb 13, 2023 | Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV. |
| CVE-2023-0817 | HIGH | 7.8 | 0.4% | Feb 13, 2023 | Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV. |
| CVE-2023-25572 | MEDIUM | 5.4 | 0.7% | Feb 13, 2023 | react-admin is a frontend framework for building browser applications on top of REST/GraphQL APIs. react-admin prior to ... |
| CVE-2023-25241 | MEDIUM | 6.1 | 0.5% | Feb 13, 2023 | bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. |
| CVE-2023-25240 | HIGH | 8.8 | 1.0% | Feb 13, 2023 | An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code. |
| CVE-2023-25162 | MEDIUM | 5.3 | 0.8% | Feb 13, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior ... |
| CVE-2023-25161 | MEDIUM | 5.3 | 0.7% | Feb 13, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne... |
| CVE-2023-25160 | MEDIUM | 5.3 | 0.5% | Feb 13, 2023 | Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11... |
| CVE-2023-24648 | MEDIUM | 6.1 | 0.5% | Feb 13, 2023 | Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php. |
| CVE-2023-24647 | HIGH | 7.5 | 0.7% | Feb 13, 2023 | Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter. |
| CVE-2023-24646 | CRITICAL | 9.8 | 1.1% | Feb 13, 2023 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attacker... |
| CVE-2023-24086 | MEDIUM | 6.1 | 0.5% | Feb 13, 2023 | SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/l... |
| CVE-2023-24084 | CRITICAL | 9.8 | 0.9% | Feb 13, 2023 | ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. |
| CVE-2023-25719 | HIGH | 8.8 | 1.1% | Feb 13, 2023 | ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such ... |
| CVE-2023-25718 | CRITICAL | 9.8 | 0.7% | Feb 13, 2023 | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio... |
| CVE-2023-25717 | CRITICAL | 9.8 | 95.1% | Feb 13, 2023 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now