2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0464 | HIGH | 7.5 | 3.7% | Mar 22, 2023 | A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 ... |
| CVE-2023-1578 | HIGH | 8.8 | 65.1% | Mar 22, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. |
| CVE-2023-1281 | HIGH | 7.8 | 0.3% | Mar 22, 2023 | Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imp... |
| CVE-2023-1559 | HIGH | 7.2 | 0.9% | Mar 22, 2023 | A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vu... |
| CVE-2023-28685 | HIGH | 7.1 | 0.6% | Mar 22, 2023 | Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack... |
| CVE-2023-25924 | HIGH | 8.8 | 0.4% | Mar 22, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform... |
| CVE-2023-25594 | HIGH | 8.8 | 0.5% | Mar 22, 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only pri... |
| CVE-2023-25590 | HIGH | 7.8 | 0.2% | Mar 22, 2023 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us... |
| CVE-2023-25069 | HIGH | 8.8 | 1.0% | Mar 22, 2023 | TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 tha... |
| CVE-2023-1436 | HIGH | 7.5 | 1.0% | Mar 22, 2023 | An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-refe... |
| CVE-2023-1370 | HIGH | 7.5 | 1.1% | Mar 22, 2023 | [Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ o... |
| CVE-2023-1168 | HIGH | 8.8 | 1.1% | Mar 22, 2023 | An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful e... |
| CVE-2023-27857 | HIGH | 7.5 | 18.3% | Mar 22, 2023 | In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than i... |
| CVE-2023-27856 | HIGH | 7.5 | 76.1% | Mar 22, 2023 | In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManage... |
| CVE-2023-24709 | HIGH | 7.5 | 44.2% | Mar 21, 2023 | An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l... |
| CVE-2023-1534 | HIGH | 8.8 | 1.3% | Mar 21, 2023 | Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the r... |
| CVE-2023-1533 | HIGH | 8.8 | 0.9% | Mar 21, 2023 | Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit h... |
| CVE-2023-1532 | HIGH | 8.8 | 1.3% | Mar 21, 2023 | Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploi... |
| CVE-2023-1531 | HIGH | 8.8 | 2.9% | Mar 21, 2023 | Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-1530 | HIGH | 8.8 | 0.8% | Mar 21, 2023 | Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2023-1528 | HIGH | 8.8 | 0.8% | Mar 21, 2023 | Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the r... |
| CVE-2023-0391 | HIGH | 8.1 | 0.6% | Mar 21, 2023 | MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, s... |
| CVE-2023-27087 | HIGH | 7.5 | 0.6% | Mar 21, 2023 | Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive infor... |
| CVE-2023-1306 | HIGH | 8.8 | 1.2% | Mar 21, 2023 | An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jin... |
| CVE-2023-1305 | HIGH | 8.1 | 0.8% | Mar 21, 2023 | An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided tho... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now