2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51384 | MEDIUM | 5.5 | 0.4% | Dec 18, 2023 | In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constr... |
| CVE-2023-48795 | MEDIUM | 5.9 | 94.1% | Dec 18, 2023 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot... |
| CVE-2023-6778 | MEDIUM | 5.4 | 0.4% | Dec 18, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. |
| CVE-2023-5236 | MEDIUM | 6.5 | 0.9% | Dec 18, 2023 | A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated at... |
| CVE-2023-5115 | MEDIUM | 6.3 | 0.9% | Dec 18, 2023 | An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a mal... |
| CVE-2023-5056 | MEDIUM | 4.1 | 0.3% | Dec 18, 2023 | A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul... |
| CVE-2023-3629 | MEDIUM | 6.5 | 0.6% | Dec 18, 2023 | A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permission... |
| CVE-2023-3628 | MEDIUM | 6.5 | 0.6% | Dec 18, 2023 | A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. ... |
| CVE-2023-35867 | MEDIUM | 5.9 | 0.6% | Dec 18, 2023 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthe... |
| CVE-2023-28053 | MEDIUM | 5.3 | 0.4% | Dec 18, 2023 | Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SS... |
| CVE-2023-6911 | MEDIUM | 4.8 | 0.4% | Dec 18, 2023 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting... |
| CVE-2023-6908 | MEDIUM | 5.9 | 0.8% | Dec 18, 2023 | A vulnerability, which was classified as problematic, was found in DFIRKuiper Kuiper 2.3.4. This affects the function un... |
| CVE-2023-50979 | MEDIUM | 5.9 | 0.6% | Dec 18, 2023 | Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding. |
| CVE-2023-6896 | MEDIUM | 6.1 | 0.6% | Dec 17, 2023 | A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue... |
| CVE-2023-6894 | MEDIUM | 6.5 | 1.0% | Dec 17, 2023 | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified ... |
| CVE-2023-6890 | MEDIUM | 5.4 | 0.5% | Dec 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17. |
| CVE-2023-6889 | MEDIUM | 5.4 | 0.5% | Dec 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17. |
| CVE-2023-28022 | MEDIUM | 6.5 | 0.5% | Dec 15, 2023 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2023-27317 | MEDIUM | 4.6 | 0.4% | Dec 15, 2023 | ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached ... |
| CVE-2023-50266 | MEDIUM | 5.3 | 0.6% | Dec 15, 2023 | Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate ... |
| CVE-2023-50720 | MEDIUM | 5.3 | 59.1% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in X... |
| CVE-2023-6051 | MEDIUM | 6.5 | 0.6% | Dec 15, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 befor... |
| CVE-2023-5512 | MEDIUM | 5.7 | 0.5% | Dec 15, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from ... |
| CVE-2023-5310 | MEDIUM | 6.5 | 0.3% | Dec 15, 2023 | A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v... |
| CVE-2023-5061 | MEDIUM | 4.3 | 0.4% | Dec 15, 2023 | An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting fro... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now