2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-30840HIGH7.8Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applicatio...
CVE-2023-30837HIGH7.5Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflo...
CVE-2023-30551HIGH7.5Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of mem...
CVE-2023-22790HIGH8.8Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf...
CVE-2023-22789HIGH8.8Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf...
CVE-2023-22788HIGH8.8Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf...
CVE-2023-22787HIGH7.5An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by ...
CVE-2023-2114HIGH7.2The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user i...
CVE-2023-1408HIGH7.2The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in...
CVE-2023-1347HIGH7.2The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which coul...
CVE-2023-0768HIGH8.8The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortco...
CVE-2023-0603HIGH8.8The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is mis...
CVE-2023-2575HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability,...
CVE-2023-2574HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the de...
CVE-2023-2573HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NT...
CVE-2023-31038HIGH8.8SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the databas...
CVE-2023-2534HIGH8.1Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacke...
CVE-2023-30257HIGH7.8A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privil...
CVE-2023-32290HIGH7.5The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
CVE-2023-29963HIGH7.2S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin...
CVE-2023-29350HIGH7.5Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-30065HIGH8.8MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) v...
CVE-2023-2554HIGH7.2External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
CVE-2023-2552HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.
CVE-2023-2551HIGH8.8PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now