2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0971 | HIGH | 8.8 | 0.3% | Jun 21, 2023 | A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration... |
| CVE-2023-2911 | HIGH | 7.5 | 2.6% | Jun 21, 2023 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `st... |
| CVE-2023-2829 | HIGH | 7.5 | 0.9% | Jun 21, 2023 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validat... |
| CVE-2023-2828 | HIGH | 7.5 | 3.8% | Jun 21, 2023 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the... |
| CVE-2023-0026 | HIGH | 7.5 | 0.6% | Jun 21, 2023 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O... |
| CVE-2023-27243 | HIGH | 7.5 | 0.4% | Jun 21, 2023 | An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a... |
| CVE-2023-34981 | HIGH | 7.5 | 1.1% | Jun 21, 2023 | A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response di... |
| CVE-2023-3339 | HIGH | 7.5 | 0.6% | Jun 21, 2023 | A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected b... |
| CVE-2023-35166 | HIGH | 8.8 | 63.1% | Jun 20, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t... |
| CVE-2023-32274 | HIGH | 7.5 | 0.6% | Jun 20, 2023 | Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android applica... |
| CVE-2023-2533 | HIGH | 8.8 | 29.5% | Jun 20, 2023 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific condition... |
| CVE-2023-1999 | HIGH | 7.5 | 1.0% | Jun 20, 2023 | There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop ... |
| CVE-2023-1862 | HIGH | 7.3 | 0.8% | Jun 20, 2023 | Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe b... |
| CVE-2023-26436 | HIGH | 8.8 | 1.3% | Jun 20, 2023 | Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not proper... |
| CVE-2023-3320 | HIGH | 8.8 | 2.3% | Jun 20, 2023 | The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,... |
| CVE-2023-3312 | HIGH | 7.5 | 0.9% | Jun 19, 2023 | A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, duri... |
| CVE-2023-35843 | HIGH | 7.5 | 8.9% | Jun 19, 2023 | NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access... |
| CVE-2023-34166 | HIGH | 7.5 | 0.4% | Jun 19, 2023 | Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerabi... |
| CVE-2023-34163 | HIGH | 7.5 | 0.4% | Jun 19, 2023 | Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause... |
| CVE-2023-34162 | HIGH | 7.5 | 0.4% | Jun 19, 2023 | Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may ... |
| CVE-2023-34161 | HIGH | 7.5 | 0.4% | Jun 19, 2023 | nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability ma... |
| CVE-2023-34155 | HIGH | 7.5 | 0.4% | Jun 19, 2023 | Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this vulnerability may aff... |
| CVE-2023-31410 | HIGH | 7.4 | 0.3% | Jun 19, 2023 | A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo... |
| CVE-2023-34373 | HIGH | 8.8 | 0.2% | Jun 19, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions. |
| CVE-2023-2805 | HIGH | 7.2 | 0.9% | Jun 19, 2023 | The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now