2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36833 | MEDIUM | 6.5 | 0.3% | Jul 14, 2023 | A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36... |
| CVE-2023-3434 | MEDIUM | 5.4 | 0.4% | Jul 14, 2023 | Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. ... |
| CVE-2023-3433 | MEDIUM | 5.5 | 0.2% | Jul 14, 2023 | The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts s... |
| CVE-2023-2975 | MEDIUM | 5.3 | 0.5% | Jul 14, 2023 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries w... |
| CVE-2023-3672 | MEDIUM | 6.1 | 0.4% | Jul 14, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5. |
| CVE-2023-3649 | MEDIUM | 5.5 | 0.2% | Jul 14, 2023 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file |
| CVE-2023-3648 | MEDIUM | 5.5 | 0.2% | Jul 14, 2023 | Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or c... |
| CVE-2023-2082 | MEDIUM | 5.4 | 0.5% | Jul 14, 2023 | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions ... |
| CVE-2023-37837 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebit... |
| CVE-2023-37836 | MEDIUM | 6.5 | 0.5% | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. Thi... |
| CVE-2023-37275 | MEDIUM | 4.3 | 0.4% | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GP... |
| CVE-2023-37272 | MEDIUM | 5.4 | 0.3% | Jul 13, 2023 | JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation ... |
| CVE-2023-37849 | MEDIUM | 6.5 | 0.4% | Jul 13, 2023 | A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute ar... |
| CVE-2023-37598 | MEDIUM | 4.5 | 0.5% | Jul 13, 2023 | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of... |
| CVE-2023-37468 | MEDIUM | 5.5 | 0.2% | Jul 13, 2023 | Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LD... |
| CVE-2023-36473 | MEDIUM | 6.1 | 0.3% | Jul 13, 2023 | Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X... |
| CVE-2023-30564 | MEDIUM | 6.9 | 0.3% | Jul 13, 2023 | Alaris Systems Manager does not perform input validation during the Device Import Function. |
| CVE-2023-30562 | MEDIUM | 6.7 | 0.2% | Jul 13, 2023 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. |
| CVE-2023-30561 | MEDIUM | 6.1 | 0.2% | Jul 13, 2023 | The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read... |
| CVE-2023-34458 | MEDIUM | 5.3 | 1.1% | Jul 13, 2023 | mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a re... |
| CVE-2023-30560 | MEDIUM | 6.8 | 0.3% | Jul 13, 2023 | The configuration from the PCU can be modified without authentication using physical connection to the PCU. |
| CVE-2023-30559 | MEDIUM | 5.7 | 0.2% | Jul 13, 2023 | The firmware update package for the wireless card is not properly signed and can be modified. |
| CVE-2023-37787 | MEDIUM | 4.8 | 0.4% | Jul 13, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts o... |
| CVE-2023-37786 | MEDIUM | 4.8 | 0.5% | Jul 13, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts o... |
| CVE-2023-37785 | MEDIUM | 4.8 | 0.4% | Jul 13, 2023 | A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scr... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now