2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-38286HIGH7.5Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, ...
CVE-2023-3668HIGH7.2Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
CVE-2023-37274HIGH7.8Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-G...
CVE-2023-37273HIGH8.8Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Aut...
CVE-2023-37599HIGH7.5An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
CVE-2023-35945HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk...
CVE-2023-37463HIGH7.5cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syn...
CVE-2023-30563HIGH8.2A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
CVE-2023-31824HIGH7.5An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via...
CVE-2023-31823HIGH7.5An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information ...
CVE-2023-31821HIGH7.5An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the chan...
CVE-2023-31825HIGH7.5An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel acce...
CVE-2023-31822HIGH7.5An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channe...
CVE-2023-31820HIGH7.5An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the cha...
CVE-2023-31819HIGH7.5An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive infor...
CVE-2023-26597HIGH7.5Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Hon...
CVE-2023-25948HIGH7.5Server information leak of configuration data when an error is generated in response to a specially crafted message. See...
CVE-2023-25770HIGH7.5Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. S...
CVE-2023-25078HIGH7.5Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a sp...
CVE-2023-24480HIGH7.5Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for ...
CVE-2023-24474HIGH7.5Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
CVE-2023-23585HIGH7.5Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific con...
CVE-2023-22435HIGH7.5Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
CVE-2023-29458HIGH7.5Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too...
CVE-2023-29451HIGH7.5Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server o...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now