2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-26490HIGH8.8mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - wh...
CVE-2023-23929HIGH8.8vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t...
CVE-2023-25403HIGH7.5CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored...
CVE-2023-25402HIGH7.5CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, ...
CVE-2023-27567HIGH7.5In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
CVE-2023-26492HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side R...
CVE-2023-26213HIGH7.2On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injectio...
CVE-2023-27566HIGH7.8Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info T...
CVE-2023-27561HIGH7runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linu...
CVE-2023-26604HIGH7.8systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible su...
CVE-2023-20088HIGH7.5A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse co...
CVE-2023-20079HIGH7.5Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated...
CVE-2023-1165HIGH7.2A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown pa...
CVE-2023-1164HIGH7.8A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is...
CVE-2023-1162HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1...
CVE-2023-27560HIGH7.5Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
CVE-2023-0457HIGH7.5Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series,...
CVE-2023-1101HIGH8.8SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use exce...
CVE-2023-0656HIGH7.5A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S...
CVE-2023-22381HIGH8.8A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment var...
CVE-2023-26476HIGH7.5XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fiel...
CVE-2023-26475HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execut...
CVE-2023-26474HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing docu...
CVE-2023-26472HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with th...
CVE-2023-26471HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now