2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40035 | HIGH | 7.2 | 1.9% | Aug 23, 2023 | Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can le... |
| CVE-2023-40025 | HIGH | 7.1 | 0.5% | Aug 23, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version ... |
| CVE-2023-40612 | HIGH | 8 | 0.4% | Aug 23, 2023 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FI... |
| CVE-2023-20169 | HIGH | 7.4 | 0.3% | Aug 23, 2023 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco... |
| CVE-2023-38831 | HIGH | 7.8 | 97.8% | Aug 23, 2023 | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a... |
| CVE-2023-40273 | HIGH | 8 | 1.4% | Aug 23, 2023 | The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the... |
| CVE-2023-37379 | HIGH | 8.1 | 1.5% | Aug 23, 2023 | Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated ... |
| CVE-2023-1409 | HIGH | 7.5 | 0.4% | Aug 23, 2023 | If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options ... |
| CVE-2023-3899 | HIGH | 7.8 | 0.3% | Aug 23, 2023 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization... |
| CVE-2023-41105 | HIGH | 7.5 | 2.2% | Aug 23, 2023 | An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), ... |
| CVE-2023-40144 | HIGH | 8.8 | 1.6% | Aug 23, 2023 | OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS... |
| CVE-2023-40158 | HIGH | 8.8 | 0.9% | Aug 23, 2023 | Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS... |
| CVE-2023-38585 | HIGH | 8.8 | 0.8% | Aug 23, 2023 | Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary... |
| CVE-2023-3495 | HIGH | 7.8 | 0.2% | Aug 23, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attac... |
| CVE-2023-39985 | HIGH | 7.8 | 0.2% | Aug 23, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers t... |
| CVE-2023-39984 | HIGH | 7.8 | 0.2% | Aug 23, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in... |
| CVE-2023-4431 | HIGH | 8.1 | 0.9% | Aug 23, 2023 | Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an ou... |
| CVE-2023-4430 | HIGH | 8.8 | 8.8% | Aug 23, 2023 | Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-4429 | HIGH | 8.8 | 0.9% | Aug 23, 2023 | Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-4428 | HIGH | 8.1 | 10.9% | Aug 23, 2023 | Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out ... |
| CVE-2023-4427 | HIGH | 8.1 | 34.0% | Aug 23, 2023 | Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out o... |
| CVE-2023-39026 | HIGH | 7.5 | 10.6% | Aug 22, 2023 | Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t... |
| CVE-2023-33850 | HIGH | 7.5 | 0.9% | Aug 22, 2023 | IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in... |
| CVE-2023-39141 | HIGH | 7.5 | 3.1% | Aug 22, 2023 | webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. |
| CVE-2023-37434 | HIGH | 8.1 | 0.7% | Aug 22, 2023 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now