2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39288MEDIUM5.5A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an au...
CVE-2023-39287MEDIUM5.5A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an au...
CVE-2023-41080MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issu...
CVE-2023-40587MEDIUM5.3Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impac...
CVE-2023-40166MEDIUM5.5Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read over...
CVE-2023-40164MEDIUM5.5Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read ov...
CVE-2023-38712MEDIUM6.5An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet cont...
CVE-2023-38711MEDIUM6.5An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID...
CVE-2023-38710MEDIUM6.5An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol...
CVE-2023-32678MEDIUM6.5Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used ...
CVE-2023-2906MEDIUM6.5Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 throug...
CVE-2023-40580MEDIUM6.5Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phra...
CVE-2023-40579MEDIUM6.5OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of Op...
CVE-2023-40036MEDIUM5.5Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read ov...
CVE-2023-39707MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attack...
CVE-2023-39600MEDIUM6.1IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-24620MEDIUM5.5An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expans...
CVE-2023-25848MEDIUM5.3ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz...
CVE-2023-38201MEDIUM6.5A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent regi...
CVE-2023-4534MEDIUM6.1A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is a...
CVE-2023-40802MEDIUM6.5The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authenticati...
CVE-2023-41167MEDIUM4.8@webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to rend...
CVE-2023-39742MEDIUM5.5giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.
CVE-2023-41250MEDIUM6.1In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
CVE-2023-41249MEDIUM6.1In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now