2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30623 | HIGH | 8.8 | 3.7% | Apr 24, 2023 | `embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.p... |
| CVE-2023-30626 | HIGH | 8.1 | 2.0% | Apr 24, 2023 | Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory ... |
| CVE-2023-2260 | HIGH | 8.8 | 0.9% | Apr 24, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. |
| CVE-2023-2259 | HIGH | 7.2 | 1.1% | Apr 24, 2023 | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2... |
| CVE-2023-2258 | HIGH | 8.8 | 0.9% | Apr 24, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. |
| CVE-2023-2006 | HIGH | 7 | 0.4% | Apr 24, 2023 | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This is... |
| CVE-2023-2257 | HIGH | 7.8 | 0.2% | Apr 24, 2023 | Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and... |
| CVE-2023-29780 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send mal... |
| CVE-2023-0388 | HIGH | 8.8 | 0.9% | Apr 24, 2023 | The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2023-27991 | HIGH | 8.8 | 1.5% | Apr 24, 2023 | The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 th... |
| CVE-2023-26099 | HIGH | 7.1 | 0.2% | Apr 24, 2023 | An issue was discovered in Telindus Apsal 3.14.2022.235 b. The consultation permission is insecure. |
| CVE-2023-26060 | HIGH | 8.8 | 0.6% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Se... |
| CVE-2023-22917 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32,... |
| CVE-2023-22916 | HIGH | 8.1 | 0.7% | Apr 24, 2023 | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00... |
| CVE-2023-22915 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 ... |
| CVE-2023-22914 | HIGH | 7.2 | 1.0% | Apr 24, 2023 | A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 th... |
| CVE-2023-22913 | HIGH | 8.1 | 1.3% | Apr 24, 2023 | A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series... |
| CVE-2023-30622 | HIGH | 8.8 | 0.2% | Apr 24, 2023 | Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in cl... |
| CVE-2023-24822 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-24821 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-2251 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5. |
| CVE-2023-29849 | HIGH | 8.8 | 3.2% | Apr 24, 2023 | Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice... |
| CVE-2023-29480 | HIGH | 7.5 | 0.4% | Apr 24, 2023 | Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use. |
| CVE-2023-24820 | HIGH | 7.5 | 0.9% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-24818 | HIGH | 7.5 | 1.2% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now