2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40035HIGH7.2Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can le...
CVE-2023-40025HIGH7.1Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version ...
CVE-2023-40612HIGH8In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FI...
CVE-2023-20169HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco...
CVE-2023-38831HIGH7.8RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a...
CVE-2023-40273HIGH8The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the...
CVE-2023-37379HIGH8.1Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated ...
CVE-2023-1409HIGH7.5If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options ...
CVE-2023-3899HIGH7.8A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization...
CVE-2023-41105HIGH7.5An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), ...
CVE-2023-40144HIGH8.8OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS...
CVE-2023-40158HIGH8.8Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS...
CVE-2023-38585HIGH8.8Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary...
CVE-2023-3495HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attac...
CVE-2023-39985HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers t...
CVE-2023-39984HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in...
CVE-2023-4431HIGH8.1Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an ou...
CVE-2023-4430HIGH8.8Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ...
CVE-2023-4429HIGH8.8Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ...
CVE-2023-4428HIGH8.1Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out ...
CVE-2023-4427HIGH8.1Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out o...
CVE-2023-39026HIGH7.5Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t...
CVE-2023-33850HIGH7.5IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in...
CVE-2023-39141HIGH7.5webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
CVE-2023-37434HIGH8.1Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now