2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30840 | HIGH | 7.8 | 0.2% | May 8, 2023 | Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applicatio... |
| CVE-2023-30837 | HIGH | 7.5 | 0.7% | May 8, 2023 | Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflo... |
| CVE-2023-30551 | HIGH | 7.5 | 1.1% | May 8, 2023 | Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of mem... |
| CVE-2023-22790 | HIGH | 8.8 | 1.7% | May 8, 2023 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf... |
| CVE-2023-22789 | HIGH | 8.8 | 1.7% | May 8, 2023 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf... |
| CVE-2023-22788 | HIGH | 8.8 | 1.7% | May 8, 2023 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf... |
| CVE-2023-22787 | HIGH | 7.5 | 0.8% | May 8, 2023 | An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by ... |
| CVE-2023-2114 | HIGH | 7.2 | 43.0% | May 8, 2023 | The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user i... |
| CVE-2023-1408 | HIGH | 7.2 | 3.2% | May 8, 2023 | The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in... |
| CVE-2023-1347 | HIGH | 7.2 | 16.0% | May 8, 2023 | The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which coul... |
| CVE-2023-0768 | HIGH | 8.8 | 0.9% | May 8, 2023 | The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortco... |
| CVE-2023-0603 | HIGH | 8.8 | 13.9% | May 8, 2023 | The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is mis... |
| CVE-2023-2575 | HIGH | 8.8 | 16.7% | May 8, 2023 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability,... |
| CVE-2023-2574 | HIGH | 8.8 | 4.8% | May 8, 2023 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the de... |
| CVE-2023-2573 | HIGH | 8.8 | 4.8% | May 8, 2023 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NT... |
| CVE-2023-31038 | HIGH | 8.8 | 1.6% | May 8, 2023 | SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the databas... |
| CVE-2023-2534 | HIGH | 8.1 | 0.5% | May 8, 2023 | Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacke... |
| CVE-2023-30257 | HIGH | 7.8 | 0.4% | May 8, 2023 | A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privil... |
| CVE-2023-32290 | HIGH | 7.5 | 0.4% | May 7, 2023 | The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server. |
| CVE-2023-29963 | HIGH | 7.2 | 1.6% | May 5, 2023 | S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin... |
| CVE-2023-29350 | HIGH | 7.5 | 2.6% | May 5, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-30065 | HIGH | 8.8 | 1.3% | May 5, 2023 | MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) v... |
| CVE-2023-2554 | HIGH | 7.2 | 31.2% | May 5, 2023 | External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0. |
| CVE-2023-2552 | HIGH | 8.8 | 0.4% | May 5, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. |
| CVE-2023-2551 | HIGH | 8.8 | 1.9% | May 5, 2023 | PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now