2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-29905MEDIUM4.9H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/a...
CVE-2023-1998MEDIUM5.6The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which di...
CVE-2023-29575MEDIUM5.5Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
CVE-2023-2228MEDIUM6.8Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-2226MEDIUM5.3Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows att...
CVE-2023-2220MEDIUM6.1A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an un...
CVE-2023-26100MEDIUM6.1In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could ...
CVE-2023-2219MEDIUM6.1A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects s...
CVE-2023-2216MEDIUM6.1A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerabil...
CVE-2023-2202MEDIUM6.5Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
CVE-2023-27354MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sono...
CVE-2023-27353MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sono...
CVE-2023-2194MEDIUM6.7An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->blo...
CVE-2023-2177MEDIUM5.5A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If s...
CVE-2023-28459MEDIUM6.5pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft...
CVE-2023-28458MEDIUM4.3pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over...
CVE-2023-27090MEDIUM5.4Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via ...
CVE-2023-22846MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s...
CVE-2023-22354MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe...
CVE-2023-22321MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci...
CVE-2023-22295MEDIUM5.5Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall...
CVE-2023-30616MEDIUM6.5Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-S...
CVE-2023-27495MEDIUM6.5@fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enfor...
CVE-2023-23938MEDIUM4.8Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are...
CVE-2023-1255MEDIUM5.9Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now