2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29994 | HIGH | 7.5 | 0.7% | May 4, 2023 | In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c. |
| CVE-2023-24958 | HIGH | 8.8 | 1.1% | May 4, 2023 | A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow a... |
| CVE-2023-25934 | HIGH | 7.5 | 0.3% | May 4, 2023 | DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacke... |
| CVE-2023-26125 | HIGH | 7.3 | 0.9% | May 4, 2023 | Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an... |
| CVE-2023-29842 | HIGH | 8.8 | 1.3% | May 4, 2023 | ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST para... |
| CVE-2023-31099 | HIGH | 8.8 | 81.6% | May 4, 2023 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe serve... |
| CVE-2023-27568 | HIGH | 8.8 | 1.2% | May 4, 2023 | SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderS... |
| CVE-2023-25438 | HIGH | 7.8 | 2.1% | May 4, 2023 | An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat... |
| CVE-2023-2182 | HIGH | 8.8 | 1.0% | May 3, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starti... |
| CVE-2023-27999 | HIGH | 7.8 | 0.5% | May 3, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 thr... |
| CVE-2023-27993 | HIGH | 7.1 | 0.2% | May 3, 2023 | A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to d... |
| CVE-2023-26203 | HIGH | 7.8 | 0.2% | May 3, 2023 | A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9... |
| CVE-2023-22640 | HIGH | 8.8 | 0.9% | May 3, 2023 | A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS ver... |
| CVE-2023-0805 | HIGH | 8.1 | 0.8% | May 3, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting... |
| CVE-2023-0756 | HIGH | 8 | 1.0% | May 3, 2023 | An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.... |
| CVE-2023-25967 | HIGH | 8.8 | 0.3% | May 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions. |
| CVE-2023-29163 | HIGH | 7.5 | 0.6% | May 3, 2023 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traff... |
| CVE-2023-28742 | HIGH | 8.8 | 1.5% | May 3, 2023 | When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: ... |
| CVE-2023-28724 | HIGH | 7.1 | 0.2% | May 3, 2023 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensit... |
| CVE-2023-28656 | HIGH | 8.1 | 0.5% | May 3, 2023 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assi... |
| CVE-2023-1385 | HIGH | 8.8 | 0.3% | May 3, 2023 | Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known val... |
| CVE-2023-23790 | HIGH | 8.8 | 0.3% | May 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= ... |
| CVE-2023-28070 | HIGH | 7.8 | 0.1% | May 3, 2023 | Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A ... |
| CVE-2023-22691 | HIGH | 8.8 | 0.3% | May 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscriptio... |
| CVE-2023-2461 | HIGH | 8.8 | 0.8% | May 3, 2023 | Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now