2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39732HIGH8.2The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token a...
CVE-2023-39619HIGH7.5ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpS...
CVE-2023-39231MEDIUM6.5PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authenti...
CVE-2023-39219HIGH7.5PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java ...
CVE-2023-38041HIGH7A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p...
CVE-2023-37913HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-37912HIGH8.8XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior t...
CVE-2023-37911MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-37910HIGH8.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t...
CVE-2023-37909HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver...
CVE-2023-37908CRITICAL9.6XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cle...
CVE-2023-37283CRITICAL9.8Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Iden...
CVE-2023-36085MEDIUM6.1The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdent...
CVE-2023-34447MEDIUM6.1iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, ...
CVE-2023-34446MEDIUM6.1iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pa...
CVE-2023-34085MEDIUM4.3When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user...
CVE-2023-34056MEDIUM4.3vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privil...
CVE-2023-34048CRITICAL9.8vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious a...
CVE-2023-31582HIGH7.5jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
CVE-2023-31581CRITICAL9.8Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
CVE-2023-31580MEDIUM5.9light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authen...
CVE-2023-30912CRITICAL9.8 A remote code execution issue exists in HPE OneView.
CVE-2023-29973MEDIUM4.9Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users ...
CVE-2023-27377HIGH7.5Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application ...
CVE-2023-27376HIGH7.5Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now