2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26855 | HIGH | 7.5 | 0.7% | Apr 4, 2023 | The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed has... |
| CVE-2023-1579 | HIGH | 7.8 | 0.5% | Apr 3, 2023 | Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64. |
| CVE-2023-29218 | HIGH | 7.5 | 1.1% | Apr 3, 2023 | The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputat... |
| CVE-2023-28854 | HIGH | 8.8 | 1.6% | Apr 3, 2023 | nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A pa... |
| CVE-2023-0975 | HIGH | 7.8 | 0.2% | Apr 3, 2023 | A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/... |
| CVE-2023-1124 | HIGH | 7.2 | 1.1% | Apr 3, 2023 | The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticate... |
| CVE-2023-0820 | HIGH | 8.8 | 0.4% | Apr 3, 2023 | The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capa... |
| CVE-2023-28625 | HIGH | 7.5 | 1.3% | Apr 3, 2023 | mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID... |
| CVE-2023-26269 | HIGH | 7.8 | 0.7% | Apr 3, 2023 | Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This ... |
| CVE-2023-28683 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2023-28682 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2023-28681 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2023-28680 | HIGH | 7.5 | 0.8% | Apr 2, 2023 | Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2023-28676 | HIGH | 8.8 | 0.6% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers... |
| CVE-2023-28674 | HIGH | 8.8 | 0.4% | Apr 2, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allow... |
| CVE-2023-20559 | HIGH | 8.8 | 0.7% | Apr 2, 2023 | Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM hand... |
| CVE-2023-20558 | HIGH | 8.8 | 0.7% | Apr 2, 2023 | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler pot... |
| CVE-2023-1580 | HIGH | 7.5 | 0.6% | Apr 2, 2023 | Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker ... |
| CVE-2023-27025 | HIGH | 7.5 | 0.3% | Apr 2, 2023 | An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers ... |
| CVE-2023-1790 | HIGH | 7.5 | 0.6% | Apr 1, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Aff... |
| CVE-2023-0198 | HIGH | 7.8 | 0.3% | Apr 1, 2023 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of ope... |
| CVE-2023-0192 | HIGH | 7.8 | 0.1% | Apr 1, 2023 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privileg... |
| CVE-2023-0191 | HIGH | 7.1 | 0.2% | Apr 1, 2023 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-... |
| CVE-2023-0189 | HIGH | 7.8 | 0.3% | Apr 1, 2023 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code exe... |
| CVE-2023-0186 | HIGH | 7.1 | 0.2% | Apr 1, 2023 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write ca... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now