2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2858MEDIUM6.5NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture...
CVE-2023-2857MEDIUM6.5BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2856MEDIUM6.5VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted ca...
CVE-2023-2855MEDIUM6.5Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fi...
CVE-2023-2854MEDIUM6.5BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-28321MEDIUM5.9An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patt...
CVE-2023-28320MEDIUM5.9A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for reso...
CVE-2023-33255MEDIUM6.1An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded in...
CVE-2023-33197MEDIUM5.4Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the U...
CVE-2023-32681MEDIUM6.1Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination s...
CVE-2023-32318MEDIUM6.7Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextclo...
CVE-2023-2283MEDIUM6.5A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_...
CVE-2023-20868MEDIUM6.1NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can i...
CVE-2023-1981MEDIUM5.5A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the a...
CVE-2023-1667MEDIUM6.5A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authent...
CVE-2023-1664MEDIUM6.5A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be ena...
CVE-2023-33780MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execut...
CVE-2023-2817MEDIUM5.4A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including ...
CVE-2023-2002MEDIUM6.8A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock....
CVE-2023-20882MEDIUM5.9In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a ...
CVE-2023-0117MEDIUM5.3The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful ...
CVE-2023-33720MEDIUM6.5mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
CVE-2023-33394MEDIUM5.4skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JS...
CVE-2023-29098MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ArtistScope CopySafe Web Protection plugin <= 3.13 version...
CVE-2023-32323MEDIUM4.3Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a S...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now