2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38286 | HIGH | 7.5 | 0.9% | Jul 14, 2023 | Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, ... |
| CVE-2023-3668 | HIGH | 7.2 | 0.8% | Jul 14, 2023 | Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21. |
| CVE-2023-37274 | HIGH | 7.8 | 0.3% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-G... |
| CVE-2023-37273 | HIGH | 8.8 | 0.3% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Aut... |
| CVE-2023-37599 | HIGH | 7.5 | 3.0% | Jul 13, 2023 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory |
| CVE-2023-35945 | HIGH | 7.5 | 1.1% | Jul 13, 2023 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk... |
| CVE-2023-37463 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syn... |
| CVE-2023-30563 | HIGH | 8.2 | 0.4% | Jul 13, 2023 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. |
| CVE-2023-31824 | HIGH | 7.5 | 0.9% | Jul 13, 2023 | An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via... |
| CVE-2023-31823 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information ... |
| CVE-2023-31821 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the chan... |
| CVE-2023-31825 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel acce... |
| CVE-2023-31822 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channe... |
| CVE-2023-31820 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the cha... |
| CVE-2023-31819 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive infor... |
| CVE-2023-26597 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Hon... |
| CVE-2023-25948 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | Server information leak of configuration data when an error is generated in response to a specially crafted message. See... |
| CVE-2023-25770 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. S... |
| CVE-2023-25078 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a sp... |
| CVE-2023-24480 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for ... |
| CVE-2023-24474 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message |
| CVE-2023-23585 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific con... |
| CVE-2023-22435 | HIGH | 7.5 | 0.5% | Jul 13, 2023 | Experion server may experience a DoS due to a stack overflow when handling a specially crafted message. |
| CVE-2023-29458 | HIGH | 7.5 | 0.6% | Jul 13, 2023 | Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too... |
| CVE-2023-29451 | HIGH | 7.5 | 0.7% | Jul 13, 2023 | Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server o... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now