2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-30553MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30552MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-29520MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2023-29515MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca...
CVE-2023-29513MEDIUM4.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has vi...
CVE-2023-27043MEDIUM5.3The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wron...
CVE-2023-30606MEDIUM4.9Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator ca...
CVE-2023-30538MEDIUM5.4Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacke...
CVE-2023-29196MEDIUM6.1Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst...
CVE-2023-29002MEDIUM6.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Ciliu...
CVE-2023-28856MEDIUM6.5Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` comman...
CVE-2023-26049MEDIUM5.3Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl...
CVE-2023-26048MEDIUM5.3Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotate...
CVE-2023-25553MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit...
CVE-2023-25551MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability ...
CVE-2023-25548MEDIUM6.5 A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE e...
CVE-2023-22002MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-22001MEDIUM4.6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-22000MEDIUM4.6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-21998MEDIUM4.6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-21997MEDIUM4.3Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supp...
CVE-2023-21993MEDIUM6.5Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Form...
CVE-2023-21992MEDIUM5.4Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workf...
CVE-2023-21989MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2023-21986MEDIUM5.7Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported v...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now