2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0286 | HIGH | 7.4 | 59.5% | Feb 8, 2023 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresse... |
| CVE-2023-0217 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by... |
| CVE-2023-0216 | HIGH | 7.5 | 1.8% | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the ... |
| CVE-2023-0215 | HIGH | 7.5 | 4.5% | Feb 8, 2023 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used ... |
| CVE-2023-25396 | HIGH | 7.8 | 0.2% | Feb 8, 2023 | Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to ac... |
| CVE-2023-25152 | HIGH | 8.8 | 0.7% | Feb 8, 2023 | Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to creat... |
| CVE-2023-0690 | HIGH | 7.1 | 0.4% | Feb 8, 2023 | HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management... |
| CVE-2023-0002 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user ... |
| CVE-2023-24828 | HIGH | 8.8 | 0.7% | Feb 8, 2023 | Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate acc... |
| CVE-2023-0705 | HIGH | 7.5 | 0.7% | Feb 7, 2023 | Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition ... |
| CVE-2023-0703 | HIGH | 8.8 | 0.7% | Feb 7, 2023 | Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to eng... |
| CVE-2023-0702 | HIGH | 8.8 | 0.7% | Feb 7, 2023 | Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user t... |
| CVE-2023-0701 | HIGH | 8.8 | 0.7% | Feb 7, 2023 | Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to ... |
| CVE-2023-0699 | HIGH | 8.8 | 0.8% | Feb 7, 2023 | Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-0698 | HIGH | 8.8 | 0.6% | Feb 7, 2023 | Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of boun... |
| CVE-2023-0696 | HIGH | 8.8 | 0.6% | Feb 7, 2023 | Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2023-25194 | HIGH | 8.8 | 95.3% | Feb 7, 2023 | A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Conne... |
| CVE-2023-23696 | HIGH | 7.8 | 0.5% | Feb 7, 2023 | Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locall... |
| CVE-2023-22643 | HIGH | 7.8 | 2.4% | Feb 7, 2023 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-p... |
| CVE-2023-0706 | HIGH | 8.8 | 0.3% | Feb 7, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.... |
| CVE-2023-24827 | HIGH | 7.5 | 0.8% | Feb 7, 2023 | syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys... |
| CVE-2023-25016 | HIGH | 7.5 | 0.4% | Feb 6, 2023 | Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized... |
| CVE-2023-0669 | HIGH | 7.2 | 100.0% | Feb 6, 2023 | Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the L... |
| CVE-2023-0234 | HIGH | 8.8 | 18.0% | Feb 6, 2023 | The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL qu... |
| CVE-2023-0679 | HIGH | 8.1 | 0.7% | Feb 6, 2023 | A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been rated as critical. Affected by th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now