2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29257 | HIGH | 7.2 | 1.5% | Apr 26, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code exec... |
| CVE-2023-26286 | HIGH | 7.8 | 0.3% | Apr 26, 2023 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtim... |
| CVE-2023-2273 | HIGH | 7.5 | 0.7% | Apr 26, 2023 | Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby uns... |
| CVE-2023-26735 | HIGH | 7.5 | 0.9% | Apr 26, 2023 | blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability a... |
| CVE-2023-0045 | HIGH | 7.5 | 2.4% | Apr 25, 2023 | The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set ... |
| CVE-2023-20869 | HIGH | 8.2 | 2.0% | Apr 25, 2023 | VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in th... |
| CVE-2023-30549 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable throu... |
| CVE-2023-29012 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an un... |
| CVE-2023-29011 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy... |
| CVE-2023-29007 | HIGH | 7.8 | 6.1% | Apr 25, 2023 | Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38... |
| CVE-2023-20872 | HIGH | 8.8 | 0.9% | Apr 25, 2023 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. |
| CVE-2023-20871 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host ... |
| CVE-2023-25652 | HIGH | 7.5 | 52.2% | Apr 25, 2023 | Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38... |
| CVE-2023-30839 | HIGH | 8.8 | 1.7% | Apr 25, 2023 | PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vul... |
| CVE-2023-28089 | HIGH | 7.1 | 0.2% | Apr 25, 2023 | An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules |
| CVE-2023-28088 | HIGH | 7.8 | 0.2% | Apr 25, 2023 | An HPE OneView appliance dump may expose SAN switch administrative credentials |
| CVE-2023-23837 | HIGH | 7.5 | 0.8% | Apr 25, 2023 | No exception handling vulnerability which revealed sensitive or excessive information to users. |
| CVE-2023-28847 | HIGH | 7.5 | 0.8% | Apr 25, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.... |
| CVE-2023-29552 | HIGH | 7.5 | 65.9% | Apr 25, 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.... |
| CVE-2023-29779 | HIGH | 7.5 | 1.2% | Apr 25, 2023 | Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send ma... |
| CVE-2023-25348 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields wh... |
| CVE-2023-26098 | HIGH | 7.8 | 0.2% | Apr 25, 2023 | An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted... |
| CVE-2023-2007 | HIGH | 7.8 | 0.3% | Apr 24, 2023 | The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when pe... |
| CVE-2023-30629 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.1 through 0.3.7, the Vyper... |
| CVE-2023-30628 | HIGH | 8.8 | 3.6% | Apr 24, 2023 | Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now