2023 CVE Vulnerabilities
31,250 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1246 | HIGH | 7.5 | 0.6% | Mar 10, 2023 | Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common R... |
| CVE-2023-27851 | HIGH | 8.8 | 0.8% | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users w... |
| CVE-2023-1205 | HIGH | 8.8 | 0.3% | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints ... |
| CVE-2023-1328 | HIGH | 7.2 | 0.9% | Mar 10, 2023 | A vulnerability was found in Guizhou 115cms 4.2. It has been classified as problematic. Affected is an unknown function ... |
| CVE-2023-27161 | HIGH | 7.5 | 1.0% | Mar 10, 2023 | Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. T... |
| CVE-2023-26464 | HIGH | 7.5 | 1.9% | Mar 10, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.... |
| CVE-2023-1313 | HIGH | 8.8 | 1.0% | Mar 10, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. |
| CVE-2023-22436 | HIGH | 7.8 | 0.2% | Mar 10, 2023 | The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF... |
| CVE-2023-22301 | HIGH | 7.5 | 0.6% | Mar 10, 2023 | The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerabilit... |
| CVE-2023-27117 | HIGH | 7.8 | 0.3% | Mar 10, 2023 | WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator. |
| CVE-2023-20049 | HIGH | 7.5 | 1.0% | Mar 9, 2023 | A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Ci... |
| CVE-2023-0623 | HIGH | 7.8 | 0.2% | Mar 9, 2023 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) fi... |
| CVE-2023-0622 | HIGH | 7.8 | 0.2% | Mar 9, 2023 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) fi... |
| CVE-2023-0621 | HIGH | 7.8 | 0.2% | Mar 9, 2023 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) fil... |
| CVE-2023-27490 | HIGH | 8.8 | 0.5% | Mar 9, 2023 | NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth pro... |
| CVE-2023-27483 | HIGH | 7.5 | 0.8% | Mar 9, 2023 | crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. A... |
| CVE-2023-25573 | HIGH | 7.5 | 49.9% | Mar 9, 2023 | metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability... |
| CVE-2023-1288 | HIGH | 7.5 | 0.5% | Mar 9, 2023 | An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker t... |
| CVE-2023-1293 | HIGH | 8.1 | 0.6% | Mar 9, 2023 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue aff... |
| CVE-2023-27986 | HIGH | 7.8 | 0.5% | Mar 9, 2023 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto... |
| CVE-2023-27985 | HIGH | 7.8 | 1.1% | Mar 9, 2023 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: ... |
| CVE-2023-26948 | HIGH | 7.5 | 0.6% | Mar 9, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/downloa... |
| CVE-2023-27974 | HIGH | 7.5 | 1.0% | Mar 9, 2023 | Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for a... |
| CVE-2023-0030 | HIGH | 7.8 | 0.2% | Mar 8, 2023 | A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that cause... |
| CVE-2023-22892 | HIGH | 7.5 | 0.6% | Mar 8, 2023 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now