2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0249HIGH7.8Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attack...
CVE-2023-25163MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-r...
CVE-2023-25167MEDIUM5.7Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de...
CVE-2023-25166MEDIUM6.5formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parse...
CVE-2023-25165MEDIUM4.3Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template funct...
CVE-2023-25164HIGH7.5Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina...
CVE-2023-25151HIGH7.5opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io...
CVE-2023-25150MEDIUM5.7Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i...
CVE-2023-0751MEDIUM6.5When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once ...
CVE-2023-0401HIGH7.5A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In cas...
CVE-2023-0286HIGH7.4There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresse...
CVE-2023-0217HIGH7.5An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by...
CVE-2023-0216HIGH7.5An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the ...
CVE-2023-0215HIGH7.5The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used ...
CVE-2023-25396HIGH7.8Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to ac...
CVE-2023-25152HIGH8.8Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to creat...
CVE-2023-23475MEDIUM4.6IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-0690HIGH7.1HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management...
CVE-2023-0003MEDIUM6.5A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit...
CVE-2023-0002HIGH7.8A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user ...
CVE-2023-0001MEDIUM6.7An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste...
CVE-2023-0748MEDIUM6.1Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVE-2023-0747MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVE-2023-0744CRITICAL9.8Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0743CRITICAL9Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now