2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5764HIGH7.8A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the u...
CVE-2023-5379HIGH7.5A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JB...
CVE-2023-50252CRITICAL9.8php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that reference...
CVE-2023-50251HIGH7.5php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a ...
CVE-2023-48225CRITICAL9.1Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, an...
CVE-2023-50247HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit...
CVE-2023-49279MEDIUM5.4Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, ...
CVE-2023-49278MEDIUM5.3Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, ...
CVE-2023-49274MEDIUM5.3Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, ...
CVE-2023-41337MEDIUM6.7h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is config...
CVE-2023-34064MEDIUM4.6Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspac...
CVE-2023-6687MEDIUM6.5An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR leve...
CVE-2023-49922MEDIUM6.5An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ...
CVE-2023-49273MEDIUM5.4Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, ...
CVE-2023-49089MEDIUM6.5Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, ...
CVE-2023-49923MEDIUM6.5 An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents...
CVE-2023-48313MEDIUM6.1Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbr...
CVE-2023-43364CRITICAL9.8main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
CVE-2023-36696HIGH7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2023-36391HIGH7.8Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2023-36020MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36019HIGH7.4Microsoft Power Platform Connector Spoofing Vulnerability
CVE-2023-36012MEDIUM5.3DHCP Server Service Information Disclosure Vulnerability
CVE-2023-36011HIGH7.8Win32k Elevation of Privilege Vulnerability
CVE-2023-36010HIGH7.5Microsoft Defender Denial of Service Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now