2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24056MEDIUM5.5In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgcon...
CVE-2023-24055MEDIUM5.5KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,...
CVE-2023-24044MEDIUM6.1A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to ...
CVE-2023-0434HIGH7.5Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.
CVE-2023-22617HIGH7.5A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS...
CVE-2023-0433HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
CVE-2023-22884CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou...
CVE-2023-24042HIGH7.5A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A han...
CVE-2023-24040HIGH7.1dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during lis...
CVE-2023-24039HIGH7.8A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-pr...
CVE-2023-24038HIGH7.5The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking f...
CVE-2023-22742MEDIUM5.9libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 ...
CVE-2023-24028CRITICAL9.8In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function...
CVE-2023-24027MEDIUM6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2023-24026MEDIUM6.1In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
CVE-2023-22726HIGH8.8act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github...
CVE-2023-0052HIGH8.8SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allow...
CVE-2023-24025HIGH7.5CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forger...
CVE-2023-23607CRITICAL9.8erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauth...
CVE-2023-24021HIGH7.5Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypa...
CVE-2023-23492HIGH8.8The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerabili...
CVE-2023-23491MEDIUM6.1The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability...
CVE-2023-23490HIGH8.8The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the '...
CVE-2023-23145HIGH7.8GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsr_read_rare_full function.
CVE-2023-23144MEDIUM5.5Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now