2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-26855HIGH7.5The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed has...
CVE-2023-1579HIGH7.8Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
CVE-2023-29218HIGH7.5The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputat...
CVE-2023-28854HIGH8.8nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A pa...
CVE-2023-0975HIGH7.8 A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/...
CVE-2023-1124HIGH7.2The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticate...
CVE-2023-0820HIGH8.8The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capa...
CVE-2023-28625HIGH7.5mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID...
CVE-2023-26269HIGH7.8Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This ...
CVE-2023-28683HIGH8.2Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external enti...
CVE-2023-28682HIGH8.2Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2023-28681HIGH8.2Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external enti...
CVE-2023-28680HIGH7.5Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2023-28676HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers...
CVE-2023-28674HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allow...
CVE-2023-20559HIGH8.8 Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM hand...
CVE-2023-20558HIGH8.8 Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler pot...
CVE-2023-1580HIGH7.5Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker ...
CVE-2023-27025HIGH7.5An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers ...
CVE-2023-1790HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Aff...
CVE-2023-0198HIGH7.8NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of ope...
CVE-2023-0192HIGH7.8NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privileg...
CVE-2023-0191HIGH7.1NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-...
CVE-2023-0189HIGH7.8NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code exe...
CVE-2023-0186HIGH7.1NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write ca...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now