2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2928 | HIGH | 8.8 | 51.4% | May 27, 2023 | A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is ... |
| CVE-2023-26129 | HIGH | 7.8 | 1.0% | May 27, 2023 | All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check'... |
| CVE-2023-26128 | HIGH | 7.8 | 1.2% | May 27, 2023 | All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or ... |
| CVE-2023-26127 | HIGH | 7.8 | 1.0% | May 27, 2023 | All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e... |
| CVE-2023-33192 | HIGH | 7.5 | 0.7% | May 27, 2023 | ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP pa... |
| CVE-2023-32688 | HIGH | 7.5 | 0.9% | May 27, 2023 | parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can ... |
| CVE-2023-32676 | HIGH | 7.2 | 0.9% | May 26, 2023 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo... |
| CVE-2023-32317 | HIGH | 7.2 | 0.9% | May 26, 2023 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo... |
| CVE-2023-32315 | HIGH | 7.5 | 100.0% | May 26, 2023 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based... |
| CVE-2023-32307 | HIGH | 7.5 | 1.1% | May 26, 2023 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-85... |
| CVE-2023-31128 | HIGH | 8.8 | 3.3% | May 26, 2023 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `... |
| CVE-2023-21515 | HIGH | 8.8 | 0.5% | May 26, 2023 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 al... |
| CVE-2023-21514 | HIGH | 8.8 | 0.5% | May 26, 2023 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execu... |
| CVE-2023-2879 | HIGH | 7.5 | 1.6% | May 26, 2023 | GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or cra... |
| CVE-2023-2825 | HIGH | 7.5 | 71.6% | May 26, 2023 | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a ... |
| CVE-2023-28319 | HIGH | 7.5 | 2.5% | May 26, 2023 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's publ... |
| CVE-2023-33247 | HIGH | 7.5 | 0.5% | May 26, 2023 | Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthentic... |
| CVE-2023-22970 | HIGH | 7.8 | 0.5% | May 26, 2023 | Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. |
| CVE-2023-33779 | HIGH | 8.8 | 1.1% | May 26, 2023 | A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another use... |
| CVE-2023-31227 | HIGH | 7.5 | 0.4% | May 26, 2023 | The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may... |
| CVE-2023-31226 | HIGH | 7.5 | 0.4% | May 26, 2023 | The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vul... |
| CVE-2023-20883 | HIGH | 7.5 | 0.9% | May 26, 2023 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, th... |
| CVE-2023-0116 | HIGH | 7.5 | 0.5% | May 26, 2023 | The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerabi... |
| CVE-2023-33440 | HIGH | 7.2 | 14.5% | May 26, 2023 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u... |
| CVE-2023-33439 | HIGH | 7.2 | 3.3% | May 26, 2023 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now