2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0299CRITICAL9.8Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
CVE-2023-22602HIGH7.5When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an auth...
CVE-2023-0298MEDIUM6.5Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
CVE-2023-0297CRITICAL9.8Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
CVE-2023-22851HIGH7.2Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unse...
CVE-2023-22850HIGH8.8Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an...
CVE-2023-22497CRITICAL9.1Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an ...
CVE-2023-23589MEDIUM6.5The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not th...
CVE-2023-22853HIGH8.8Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection becau...
CVE-2023-22852MEDIUM6.5Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.
CVE-2023-22496CRITICAL9.8Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the abili...
CVE-2023-22495CRITICAL9.8Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypas...
CVE-2023-22480CRITICAL9.8KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate productio...
CVE-2023-22478HIGH7.5KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. T...
CVE-2023-22471MEDIUM4.3Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N...
CVE-2023-22470MEDIUM6.5Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2023-21599MEDIUM5.5Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that co...
CVE-2023-21598MEDIUM5.5Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could l...
CVE-2023-21597HIGH7.8Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that c...
CVE-2023-21596HIGH7.8Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability ...
CVE-2023-21595HIGH7.8Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that c...
CVE-2023-21594HIGH7.8Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability ...
CVE-2023-21592MEDIUM5.5Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that c...
CVE-2023-21591MEDIUM5.5Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that c...
CVE-2023-21590HIGH7.8Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now