2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26490 | HIGH | 8.8 | 2.2% | Mar 4, 2023 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - wh... |
| CVE-2023-23929 | HIGH | 8.8 | 0.6% | Mar 4, 2023 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t... |
| CVE-2023-25403 | HIGH | 7.5 | 0.7% | Mar 3, 2023 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored... |
| CVE-2023-25402 | HIGH | 7.5 | 0.6% | Mar 3, 2023 | CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, ... |
| CVE-2023-27567 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel. |
| CVE-2023-26492 | HIGH | 7.5 | 1.0% | Mar 3, 2023 | Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side R... |
| CVE-2023-26213 | HIGH | 7.2 | 7.9% | Mar 3, 2023 | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injectio... |
| CVE-2023-27566 | HIGH | 7.8 | 0.6% | Mar 3, 2023 | Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info T... |
| CVE-2023-27561 | HIGH | 7 | 0.4% | Mar 3, 2023 | runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linu... |
| CVE-2023-26604 | HIGH | 7.8 | 1.1% | Mar 3, 2023 | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible su... |
| CVE-2023-20088 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse co... |
| CVE-2023-20079 | HIGH | 7.5 | 10.3% | Mar 3, 2023 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated... |
| CVE-2023-1165 | HIGH | 7.2 | 0.8% | Mar 3, 2023 | A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown pa... |
| CVE-2023-1164 | HIGH | 7.8 | 0.4% | Mar 3, 2023 | A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is... |
| CVE-2023-1162 | HIGH | 8.8 | 26.0% | Mar 3, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1... |
| CVE-2023-27560 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields. |
| CVE-2023-0457 | HIGH | 7.5 | 1.2% | Mar 3, 2023 | Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series,... |
| CVE-2023-1101 | HIGH | 8.8 | 0.7% | Mar 2, 2023 | SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use exce... |
| CVE-2023-0656 | HIGH | 7.5 | 41.3% | Mar 2, 2023 | A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S... |
| CVE-2023-22381 | HIGH | 8.8 | 0.8% | Mar 2, 2023 | A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment var... |
| CVE-2023-26476 | HIGH | 7.5 | 0.9% | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fiel... |
| CVE-2023-26475 | HIGH | 8.8 | 64.5% | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execut... |
| CVE-2023-26474 | HIGH | 8.8 | 0.8% | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing docu... |
| CVE-2023-26472 | HIGH | 8.8 | 1.1% | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with th... |
| CVE-2023-26471 | HIGH | 8.8 | 0.9% | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now