2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36222MEDIUM5.4Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary...
CVE-2023-2728MEDIUM6.5Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission...
CVE-2023-2727MEDIUM6.5Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral conta...
CVE-2023-37378MEDIUM5.3Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
CVE-2023-36608MEDIUM6.5 The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
CVE-2023-36819MEDIUM6.5Knowage is the professional open source suite for modern business analytics over traditional sources and big data system...
CVE-2023-3497MEDIUM4.6Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a ...
CVE-2023-36816MEDIUM6.12FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site script...
CVE-2023-34450MEDIUM5.3CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many ...
CVE-2023-28364MEDIUM6.1An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android ...
CVE-2023-3338MEDIUM6.5A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a rem...
CVE-2023-2908MEDIUM5.5A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a craft...
CVE-2023-22815MEDIUM6.7Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an ...
CVE-2023-1206MEDIUM5.7A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user...
CVE-2023-35946MEDIUM5.5Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a...
CVE-2023-29147MEDIUM5.5In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, be...
CVE-2023-37365MEDIUM6.5Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
CVE-2023-36810MEDIUM6.5pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An ...
CVE-2023-36807MEDIUM6.5pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In ...
CVE-2023-36477MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e...
CVE-2023-37360MEDIUM6.1pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the ...
CVE-2023-37307MEDIUM5.4In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
CVE-2023-37305MEDIUM5.3An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Pa...
CVE-2023-37304MEDIUM5.4An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via...
CVE-2023-37302MEDIUM6.1An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now