2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20128 | HIGH | 7.2 | 30.4% | Apr 5, 2023 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN ... |
| CVE-2023-20124 | HIGH | 7.2 | 1.0% | Apr 5, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV... |
| CVE-2023-28634 | HIGH | 8.8 | 0.8% | Apr 5, 2023 | GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.... |
| CVE-2023-20051 | HIGH | 7.5 | 0.9% | Apr 5, 2023 | A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthent... |
| CVE-2023-22660 | HIGH | 7.8 | 0.5% | Apr 5, 2023 | A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutB... |
| CVE-2023-22291 | HIGH | 7.8 | 0.5% | Apr 5, 2023 | An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially ... |
| CVE-2023-1412 | HIGH | 7.8 | 0.2% | Apr 5, 2023 | An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for ... |
| CVE-2023-28632 | HIGH | 8.1 | 0.7% | Apr 5, 2023 | GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.... |
| CVE-2023-26857 | HIGH | 7.2 | 0.9% | Apr 5, 2023 | An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0... |
| CVE-2023-26856 | HIGH | 7.2 | 0.7% | Apr 5, 2023 | Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter a... |
| CVE-2023-1858 | HIGH | 7.5 | 0.6% | Apr 5, 2023 | A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic.... |
| CVE-2023-29323 | HIGH | 7.8 | 0.3% | Apr 4, 2023 | ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7... |
| CVE-2023-0835 | HIGH | 8.2 | 0.6% | Apr 4, 2023 | markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible becau... |
| CVE-2023-0480 | HIGH | 8.8 | 0.3% | Apr 4, 2023 | VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. Thi... |
| CVE-2023-29003 | HIGH | 8.8 | 0.6% | Apr 4, 2023 | SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs... |
| CVE-2023-28840 | HIGH | 8.7 | 2.7% | Apr 4, 2023 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Ru... |
| CVE-2023-1820 | HIGH | 8.8 | 1.0% | Apr 4, 2023 | Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced ... |
| CVE-2023-1818 | HIGH | 8.8 | 0.9% | Apr 4, 2023 | Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-1815 | HIGH | 8.8 | 0.9% | Apr 4, 2023 | Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user... |
| CVE-2023-1812 | HIGH | 8.8 | 0.9% | Apr 4, 2023 | Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform... |
| CVE-2023-1811 | HIGH | 8.8 | 1.0% | Apr 4, 2023 | Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engag... |
| CVE-2023-1810 | HIGH | 8.8 | 1.1% | Apr 4, 2023 | Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised th... |
| CVE-2023-0265 | HIGH | 8.8 | 1.6% | Apr 4, 2023 | Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because... |
| CVE-2023-27496 | HIGH | 7.5 | 0.8% | Apr 4, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,... |
| CVE-2023-27091 | HIGH | 7.2 | 0.7% | Apr 4, 2023 | An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and key... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now