2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21152 | MEDIUM | 5.5 | 0.1% | Jun 28, 2023 | In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a m... |
| CVE-2023-21151 | MEDIUM | 6.7 | 0.1% | Jun 28, 2023 | In the Google BMS kernel module, there is a possible out of bounds write due to a heap buffer overflow. This could lead ... |
| CVE-2023-21150 | MEDIUM | 4.4 | 0.1% | Jun 28, 2023 | In handle_set_parameters_ctrl of hal_socket.c, there is a possible out of bounds read due to an incorrect bounds check. ... |
| CVE-2023-21148 | MEDIUM | 4.4 | 0.1% | Jun 28, 2023 | In BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing null check. This co... |
| CVE-2023-21146 | MEDIUM | 6.7 | 0.1% | Jun 28, 2023 | there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with... |
| CVE-2023-20199 | MEDIUM | 6.6 | 0.3% | Jun 28, 2023 | A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypa... |
| CVE-2023-20188 | MEDIUM | 4.8 | 0.5% | Jun 28, 2023 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus... |
| CVE-2023-20136 | MEDIUM | 6.5 | 0.5% | Jun 28, 2023 | A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privilege... |
| CVE-2023-20120 | MEDIUM | 6.1 | 0.5% | Jun 28, 2023 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ... |
| CVE-2023-20119 | MEDIUM | 6.1 | 0.5% | Jun 28, 2023 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, ... |
| CVE-2023-20116 | MEDIUM | 5.7 | 0.6% | Jun 28, 2023 | A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and... |
| CVE-2023-20105 | MEDIUM | 6.5 | 0.9% | Jun 28, 2023 | A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communicati... |
| CVE-2023-20028 | MEDIUM | 5.4 | 0.5% | Jun 28, 2023 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web ... |
| CVE-2023-3445 | MEDIUM | 4.8 | 0.5% | Jun 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. |
| CVE-2023-30259 | MEDIUM | 5.5 | 0.3% | Jun 28, 2023 | A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information v... |
| CVE-2023-3034 | MEDIUM | 6.1 | 0.3% | Jun 28, 2023 | Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44 |
| CVE-2023-3407 | MEDIUM | 4.3 | 0.3% | Jun 28, 2023 | The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40.... |
| CVE-2023-1844 | MEDIUM | 4.3 | 0.4% | Jun 28, 2023 | The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capabil... |
| CVE-2023-3427 | MEDIUM | 4.3 | 0.2% | Jun 28, 2023 | The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2023-3332 | MEDIUM | 4.8 | 0.3% | Jun 28, 2023 | Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26... |
| CVE-2023-3331 | MEDIUM | 5.4 | 0.5% | Jun 28, 2023 | Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26... |
| CVE-2023-3330 | MEDIUM | 4.3 | 0.4% | Jun 28, 2023 | Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, ... |
| CVE-2023-36464 | MEDIUM | 5.5 | 0.3% | Jun 27, 2023 | pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an inf... |
| CVE-2023-36463 | MEDIUM | 6.1 | 0.4% | Jun 27, 2023 | Meldekarten generator is an open source project to create a program, running locally in the browser without the need for... |
| CVE-2023-23468 | MEDIUM | 5.5 | 0.2% | Jun 27, 2023 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insuffic... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now