2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30539 | HIGH | 8.8 | 0.6% | Apr 17, 2023 | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to l... |
| CVE-2023-29213 | HIGH | 8.8 | 0.4% | Apr 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2023-29197 | HIGH | 7.5 | 1.2% | Apr 17, 2023 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header ... |
| CVE-2023-28983 | HIGH | 8.8 | 1.5% | Apr 17, 2023 | An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Juno... |
| CVE-2023-28982 | HIGH | 7.5 | 0.6% | Apr 17, 2023 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Ju... |
| CVE-2023-28976 | HIGH | 7.5 | 0.6% | Apr 17, 2023 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N... |
| CVE-2023-28973 | HIGH | 7.1 | 0.1% | Apr 17, 2023 | An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a l... |
| CVE-2023-28971 | HIGH | 7.2 | 0.4% | Apr 17, 2023 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Junip... |
| CVE-2023-28967 | HIGH | 7.5 | 0.6% | Apr 17, 2023 | A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS... |
| CVE-2023-28966 | HIGH | 7.8 | 0.2% | Apr 17, 2023 | An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attack... |
| CVE-2023-28965 | HIGH | 7.5 | 0.6% | Apr 17, 2023 | An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS al... |
| CVE-2023-28964 | HIGH | 7.5 | 0.6% | Apr 17, 2023 | An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Net... |
| CVE-2023-28960 | HIGH | 8.2 | 0.2% | Apr 17, 2023 | An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a loc... |
| CVE-2023-27911 | HIGH | 7.8 | 0.6% | Apr 17, 2023 | A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodes... |
| CVE-2023-27910 | HIGH | 7.8 | 0.5% | Apr 17, 2023 | A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autode... |
| CVE-2023-27909 | HIGH | 7.8 | 0.5% | Apr 17, 2023 | An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through mali... |
| CVE-2023-27907 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerabili... |
| CVE-2023-27906 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerabilit... |
| CVE-2023-25010 | HIGH | 7.8 | 0.3% | Apr 17, 2023 | A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which ma... |
| CVE-2023-27705 | HIGH | 7.5 | 0.8% | Apr 17, 2023 | APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. |
| CVE-2023-1831 | HIGH | 7.5 | 0.4% | Apr 17, 2023 | Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op... |
| CVE-2023-27755 | HIGH | 8.8 | 0.8% | Apr 17, 2023 | go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. |
| CVE-2023-27733 | HIGH | 7.2 | 0.8% | Apr 17, 2023 | DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php. |
| CVE-2023-0765 | HIGH | 8.8 | 0.9% | Apr 17, 2023 | The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to... |
| CVE-2023-0277 | HIGH | 7.2 | 0.9% | Apr 17, 2023 | The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now