2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3421 | HIGH | 8.8 | 1.1% | Jun 26, 2023 | Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-3420 | HIGH | 8.8 | 62.1% | Jun 26, 2023 | Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-34924 | HIGH | 7.5 | 0.7% | Jun 26, 2023 | H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerabili... |
| CVE-2023-34463 | HIGH | 8.1 | 0.6% | Jun 26, 2023 | DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af... |
| CVE-2023-3113 | HIGH | 7.5 | 0.4% | Jun 26, 2023 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) ser... |
| CVE-2023-35933 | HIGH | 7.5 | 0.9% | Jun 26, 2023 | OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vu... |
| CVE-2023-34420 | HIGH | 7.2 | 1.1% | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted call... |
| CVE-2023-34418 | HIGH | 8.1 | 0.5% | Jun 26, 2023 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to ... |
| CVE-2023-2992 | HIGH | 7.5 | 0.5% | Jun 26, 2023 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which ca... |
| CVE-2023-36252 | HIGH | 8.8 | 0.7% | Jun 26, 2023 | An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a... |
| CVE-2023-2005 | HIGH | 8.8 | 0.4% | Jun 26, 2023 | Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugi... |
| CVE-2023-36301 | HIGH | 7.5 | 0.8% | Jun 26, 2023 | Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet. |
| CVE-2023-25307 | HIGH | 7.8 | 0.6% | Jun 26, 2023 | nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal. |
| CVE-2023-25306 | HIGH | 7.5 | 0.9% | Jun 26, 2023 | MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal. |
| CVE-2023-36631 | HIGH | 7.8 | 0.6% | Jun 26, 2023 | Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged us... |
| CVE-2023-3398 | HIGH | 7.5 | 0.8% | Jun 26, 2023 | Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. |
| CVE-2023-1150 | HIGH | 7.5 | 0.7% | Jun 26, 2023 | Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS... |
| CVE-2023-36664 | HIGH | 7.8 | 3.2% | Jun 25, 2023 | Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | p... |
| CVE-2023-36661 | HIGH | 7.5 | 2.8% | Jun 25, 2023 | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyIn... |
| CVE-2023-36663 | HIGH | 8.8 | 0.6% | Jun 25, 2023 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the so... |
| CVE-2023-36632 | HIGH | 7.5 | 1.3% | Jun 25, 2023 | The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum ... |
| CVE-2023-36630 | HIGH | 8.8 | 0.7% | Jun 25, 2023 | In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass. |
| CVE-2023-36612 | HIGH | 7.5 | 0.8% | Jun 25, 2023 | Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an ... |
| CVE-2023-1722 | HIGH | 8.8 | 0.4% | Jun 24, 2023 | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b... |
| CVE-2023-1721 | HIGH | 7.2 | 1.0% | Jun 24, 2023 | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now