2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0249 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attack... |
| CVE-2023-25163 | MEDIUM | 6.5 | 0.8% | Feb 8, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-r... |
| CVE-2023-25167 | MEDIUM | 5.7 | 0.6% | Feb 8, 2023 | Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de... |
| CVE-2023-25166 | MEDIUM | 6.5 | 0.6% | Feb 8, 2023 | formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parse... |
| CVE-2023-25165 | MEDIUM | 4.3 | 0.8% | Feb 8, 2023 | Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template funct... |
| CVE-2023-25164 | HIGH | 7.5 | 0.7% | Feb 8, 2023 | Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina... |
| CVE-2023-25151 | HIGH | 7.5 | 1.0% | Feb 8, 2023 | opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io... |
| CVE-2023-25150 | MEDIUM | 5.7 | 0.7% | Feb 8, 2023 | Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i... |
| CVE-2023-0751 | MEDIUM | 6.5 | 0.6% | Feb 8, 2023 | When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once ... |
| CVE-2023-0401 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In cas... |
| CVE-2023-0286 | HIGH | 7.4 | 59.5% | Feb 8, 2023 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresse... |
| CVE-2023-0217 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by... |
| CVE-2023-0216 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the ... |
| CVE-2023-0215 | HIGH | 7.5 | 4.5% | Feb 8, 2023 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used ... |
| CVE-2023-25396 | HIGH | 7.8 | 0.2% | Feb 8, 2023 | Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to ac... |
| CVE-2023-25152 | HIGH | 8.8 | 0.7% | Feb 8, 2023 | Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to creat... |
| CVE-2023-23475 | MEDIUM | 4.6 | 0.3% | Feb 8, 2023 | IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-0690 | HIGH | 7.1 | 0.4% | Feb 8, 2023 | HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management... |
| CVE-2023-0003 | MEDIUM | 6.5 | 1.2% | Feb 8, 2023 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit... |
| CVE-2023-0002 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user ... |
| CVE-2023-0001 | MEDIUM | 6.7 | 0.2% | Feb 8, 2023 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste... |
| CVE-2023-0748 | MEDIUM | 6.1 | 0.6% | Feb 8, 2023 | Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. |
| CVE-2023-0747 | MEDIUM | 5.4 | 0.5% | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. |
| CVE-2023-0744 | CRITICAL | 9.8 | 6.4% | Feb 8, 2023 | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. |
| CVE-2023-0743 | CRITICAL | 9 | 0.7% | Feb 8, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now