2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0414 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture ... |
| CVE-2023-0413 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ... |
| CVE-2023-0411 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via ... |
| CVE-2023-0394 | MEDIUM | 5.5 | 1.0% | Jan 26, 2023 | A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in ... |
| CVE-2023-0229 | MEDIUM | 6.3 | 0.6% | Jan 26, 2023 | A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue t... |
| CVE-2023-0396 | MEDIUM | 6.8 | 0.4% | Jan 25, 2023 | A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command r... |
| CVE-2023-22485 | MEDIUM | 5.3 | 0.7% | Jan 24, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29... |
| CVE-2023-21719 | MEDIUM | 6.5 | 1.7% | Jan 24, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-22630 | MEDIUM | 4.3 | 0.6% | Jan 23, 2023 | IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI. |
| CVE-2023-23687 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions. |
| CVE-2023-22721 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions. |
| CVE-2023-0447 | MEDIUM | 4.3 | 0.6% | Jan 23, 2023 | The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t... |
| CVE-2023-0446 | MEDIUM | 5.5 | 0.6% | Jan 23, 2023 | The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in ... |
| CVE-2023-0440 | MEDIUM | 5.3 | 0.6% | Jan 23, 2023 | Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6. |
| CVE-2023-0438 | MEDIUM | 6.5 | 0.3% | Jan 23, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-24070 | MEDIUM | 6.1 | 0.4% | Jan 23, 2023 | app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. |
| CVE-2023-24058 | MEDIUM | 4.3 | 0.9% | Jan 22, 2023 | Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId... |
| CVE-2023-24056 | MEDIUM | 5.5 | 0.5% | Jan 22, 2023 | In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgcon... |
| CVE-2023-24055 | MEDIUM | 5.5 | 3.7% | Jan 22, 2023 | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,... |
| CVE-2023-24044 | MEDIUM | 6.1 | 2.2% | Jan 22, 2023 | A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to ... |
| CVE-2023-22742 | MEDIUM | 5.9 | 0.6% | Jan 20, 2023 | libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 ... |
| CVE-2023-24027 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. |
| CVE-2023-24026 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. |
| CVE-2023-23491 | MEDIUM | 6.1 | 1.2% | Jan 20, 2023 | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability... |
| CVE-2023-23144 | MEDIUM | 5.5 | 0.3% | Jan 20, 2023 | Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now