2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39288 | MEDIUM | 5.5 | 0.5% | Aug 25, 2023 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an au... |
| CVE-2023-39287 | MEDIUM | 5.5 | 0.5% | Aug 25, 2023 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an au... |
| CVE-2023-41080 | MEDIUM | 6.1 | 6.0% | Aug 25, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issu... |
| CVE-2023-40587 | MEDIUM | 5.3 | 0.6% | Aug 25, 2023 | Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impac... |
| CVE-2023-40166 | MEDIUM | 5.5 | 0.5% | Aug 25, 2023 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read over... |
| CVE-2023-40164 | MEDIUM | 5.5 | 0.5% | Aug 25, 2023 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read ov... |
| CVE-2023-38712 | MEDIUM | 6.5 | 0.7% | Aug 25, 2023 | An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet cont... |
| CVE-2023-38711 | MEDIUM | 6.5 | 0.7% | Aug 25, 2023 | An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID... |
| CVE-2023-38710 | MEDIUM | 6.5 | 0.7% | Aug 25, 2023 | An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol... |
| CVE-2023-32678 | MEDIUM | 6.5 | 0.4% | Aug 25, 2023 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used ... |
| CVE-2023-2906 | MEDIUM | 6.5 | 2.8% | Aug 25, 2023 | Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 throug... |
| CVE-2023-40580 | MEDIUM | 6.5 | 0.6% | Aug 25, 2023 | Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phra... |
| CVE-2023-40579 | MEDIUM | 6.5 | 0.5% | Aug 25, 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of Op... |
| CVE-2023-40036 | MEDIUM | 5.5 | 0.4% | Aug 25, 2023 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read ov... |
| CVE-2023-39707 | MEDIUM | 5.4 | 0.6% | Aug 25, 2023 | A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attack... |
| CVE-2023-39600 | MEDIUM | 6.1 | 1.2% | Aug 25, 2023 | IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter. |
| CVE-2023-24620 | MEDIUM | 5.5 | 0.4% | Aug 25, 2023 | An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expans... |
| CVE-2023-25848 | MEDIUM | 5.3 | 0.2% | Aug 25, 2023 | ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz... |
| CVE-2023-38201 | MEDIUM | 6.5 | 0.5% | Aug 25, 2023 | A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent regi... |
| CVE-2023-4534 | MEDIUM | 6.1 | 0.5% | Aug 25, 2023 | A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is a... |
| CVE-2023-40802 | MEDIUM | 6.5 | 0.7% | Aug 25, 2023 | The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authenticati... |
| CVE-2023-41167 | MEDIUM | 4.8 | 0.3% | Aug 25, 2023 | @webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to rend... |
| CVE-2023-39742 | MEDIUM | 5.5 | 0.3% | Aug 25, 2023 | giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c. |
| CVE-2023-41250 | MEDIUM | 6.1 | 0.3% | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration |
| CVE-2023-41249 | MEDIUM | 6.1 | 53.1% | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now