2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-1246HIGH7.5Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common R...
CVE-2023-27851HIGH8.8NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users w...
CVE-2023-1205HIGH8.8NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints ...
CVE-2023-1328HIGH7.2A vulnerability was found in Guizhou 115cms 4.2. It has been classified as problematic. Affected is an unknown function ...
CVE-2023-27161HIGH7.5Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. T...
CVE-2023-26464HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1....
CVE-2023-1313HIGH8.8Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
CVE-2023-22436HIGH7.8The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF...
CVE-2023-22301HIGH7.5The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerabilit...
CVE-2023-27117HIGH7.8WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
CVE-2023-20049HIGH7.5A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Ci...
CVE-2023-0623HIGH7.8Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) fi...
CVE-2023-0622HIGH7.8Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) fi...
CVE-2023-0621HIGH7.8Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) fil...
CVE-2023-27490HIGH8.8NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth pro...
CVE-2023-27483HIGH7.5crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. A...
CVE-2023-25573HIGH7.5metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability...
CVE-2023-1288HIGH7.5 An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker t...
CVE-2023-1293HIGH8.1A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue aff...
CVE-2023-27986HIGH7.8emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto...
CVE-2023-27985HIGH7.8emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: ...
CVE-2023-26948HIGH7.5onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/downloa...
CVE-2023-27974HIGH7.5Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for a...
CVE-2023-0030HIGH7.8A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that cause...
CVE-2023-22892HIGH7.5There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now