2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39558 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai... |
| CVE-2023-4611 | MEDIUM | 6.3 | 0.3% | Aug 29, 2023 | A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is ... |
| CVE-2023-4296 | MEDIUM | 6.1 | 0.6% | Aug 29, 2023 | If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to i... |
| CVE-2023-41153 | MEDIUM | 5.4 | 0.4% | Aug 29, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ... |
| CVE-2023-38971 | MEDIUM | 5.4 | 0.6% | Aug 29, 2023 | Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via... |
| CVE-2023-32241 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5... |
| CVE-2023-3253 | MEDIUM | 4.3 | 0.4% | Aug 29, 2023 | An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list... |
| CVE-2023-39678 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F ... |
| CVE-2023-39267 | MEDIUM | 6.5 | 0.7% | Aug 29, 2023 | An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful ... |
| CVE-2023-39266 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct... |
| CVE-2023-3252 | MEDIUM | 6.5 | 0.6% | Aug 29, 2023 | An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges coul... |
| CVE-2023-3251 | MEDIUM | 4.9 | 0.5% | Aug 29, 2023 | A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover st... |
| CVE-2023-39522 | MEDIUM | 5.3 | 0.5% | Aug 29, 2023 | goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage... |
| CVE-2023-41037 | MEDIUM | 4.3 | 0.3% | Aug 29, 2023 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Message... |
| CVE-2023-39615 | MEDIUM | 6.5 | 0.7% | Aug 29, 2023 | Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxm... |
| CVE-2023-24548 | MEDIUM | 6.5 | 0.5% | Aug 29, 2023 | On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tun... |
| CVE-2023-38283 | MEDIUM | 5.3 | 1.1% | Aug 29, 2023 | In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant r... |
| CVE-2023-0238 | MEDIUM | 5.5 | 0.2% | Aug 29, 2023 | Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic... |
| CVE-2023-41363 | MEDIUM | 4.3 | 0.3% | Aug 29, 2023 | In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other... |
| CVE-2023-4569 | MEDIUM | 5.5 | 0.3% | Aug 28, 2023 | A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue ... |
| CVE-2023-40781 | MEDIUM | 6.5 | 0.5% | Aug 28, 2023 | Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a cra... |
| CVE-2023-34725 | MEDIUM | 6.8 | 0.5% | Aug 28, 2023 | An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated pri... |
| CVE-2023-34724 | MEDIUM | 6.8 | 0.4% | Aug 28, 2023 | An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated priv... |
| CVE-2023-40170 | MEDIUM | 6.1 | 0.5% | Aug 28, 2023 | jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs coul... |
| CVE-2023-39968 | MEDIUM | 6.1 | 0.6% | Aug 28, 2023 | jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now