2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29905 | MEDIUM | 4.9 | 0.8% | Apr 21, 2023 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/a... |
| CVE-2023-1998 | MEDIUM | 5.6 | 1.4% | Apr 21, 2023 | The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which di... |
| CVE-2023-29575 | MEDIUM | 5.5 | 0.3% | Apr 21, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component. |
| CVE-2023-2228 | MEDIUM | 6.8 | 0.4% | Apr 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0. |
| CVE-2023-2226 | MEDIUM | 5.3 | 0.4% | Apr 21, 2023 | Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows att... |
| CVE-2023-2220 | MEDIUM | 6.1 | 0.6% | Apr 21, 2023 | A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an un... |
| CVE-2023-26100 | MEDIUM | 6.1 | 0.4% | Apr 21, 2023 | In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could ... |
| CVE-2023-2219 | MEDIUM | 6.1 | 0.5% | Apr 21, 2023 | A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects s... |
| CVE-2023-2216 | MEDIUM | 6.1 | 0.6% | Apr 21, 2023 | A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerabil... |
| CVE-2023-2202 | MEDIUM | 6.5 | 0.5% | Apr 21, 2023 | Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3. |
| CVE-2023-27354 | MEDIUM | 6.5 | 0.6% | Apr 20, 2023 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sono... |
| CVE-2023-27353 | MEDIUM | 6.5 | 0.6% | Apr 20, 2023 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sono... |
| CVE-2023-2194 | MEDIUM | 6.7 | 0.2% | Apr 20, 2023 | An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->blo... |
| CVE-2023-2177 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If s... |
| CVE-2023-28459 | MEDIUM | 6.5 | 6.6% | Apr 20, 2023 | pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft... |
| CVE-2023-28458 | MEDIUM | 4.3 | 3.4% | Apr 20, 2023 | pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over... |
| CVE-2023-27090 | MEDIUM | 5.4 | 0.4% | Apr 20, 2023 | Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via ... |
| CVE-2023-22846 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s... |
| CVE-2023-22354 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe... |
| CVE-2023-22321 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci... |
| CVE-2023-22295 | MEDIUM | 5.5 | 0.2% | Apr 20, 2023 | Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall... |
| CVE-2023-30616 | MEDIUM | 6.5 | 0.3% | Apr 20, 2023 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-S... |
| CVE-2023-27495 | MEDIUM | 6.5 | 0.3% | Apr 20, 2023 | @fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enfor... |
| CVE-2023-23938 | MEDIUM | 4.8 | 0.5% | Apr 20, 2023 | Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are... |
| CVE-2023-1255 | MEDIUM | 5.9 | 1.0% | Apr 20, 2023 | Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now