2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24056 | MEDIUM | 5.5 | 0.5% | Jan 22, 2023 | In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgcon... |
| CVE-2023-24055 | MEDIUM | 5.5 | 3.7% | Jan 22, 2023 | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,... |
| CVE-2023-24044 | MEDIUM | 6.1 | 2.2% | Jan 22, 2023 | A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to ... |
| CVE-2023-0434 | HIGH | 7.5 | 0.8% | Jan 22, 2023 | Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40. |
| CVE-2023-22617 | HIGH | 7.5 | 7.3% | Jan 21, 2023 | A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS... |
| CVE-2023-0433 | HIGH | 7.8 | 0.6% | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. |
| CVE-2023-22884 | CRITICAL | 9.8 | 11.1% | Jan 21, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou... |
| CVE-2023-24042 | HIGH | 7.5 | 0.5% | Jan 21, 2023 | A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A han... |
| CVE-2023-24040 | HIGH | 7.1 | 0.5% | Jan 21, 2023 | dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during lis... |
| CVE-2023-24039 | HIGH | 7.8 | 0.5% | Jan 21, 2023 | A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-pr... |
| CVE-2023-24038 | HIGH | 7.5 | 1.1% | Jan 21, 2023 | The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking f... |
| CVE-2023-22742 | MEDIUM | 5.9 | 0.6% | Jan 20, 2023 | libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 ... |
| CVE-2023-24028 | CRITICAL | 9.8 | 0.7% | Jan 20, 2023 | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function... |
| CVE-2023-24027 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. |
| CVE-2023-24026 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. |
| CVE-2023-22726 | HIGH | 8.8 | 1.3% | Jan 20, 2023 | act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github... |
| CVE-2023-0052 | HIGH | 8.8 | 0.7% | Jan 20, 2023 | SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allow... |
| CVE-2023-24025 | HIGH | 7.5 | 0.5% | Jan 20, 2023 | CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forger... |
| CVE-2023-23607 | CRITICAL | 9.8 | 1.6% | Jan 20, 2023 | erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauth... |
| CVE-2023-24021 | HIGH | 7.5 | 0.9% | Jan 20, 2023 | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypa... |
| CVE-2023-23492 | HIGH | 8.8 | 57.4% | Jan 20, 2023 | The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerabili... |
| CVE-2023-23491 | MEDIUM | 6.1 | 1.2% | Jan 20, 2023 | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability... |
| CVE-2023-23490 | HIGH | 8.8 | 2.3% | Jan 20, 2023 | The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the '... |
| CVE-2023-23145 | HIGH | 7.8 | 0.4% | Jan 20, 2023 | GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsr_read_rare_full function. |
| CVE-2023-23144 | MEDIUM | 5.5 | 0.3% | Jan 20, 2023 | Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now