2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22402 | MEDIUM | 5.9 | 0.5% | Jan 13, 2023 | A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-bas... |
| CVE-2023-22398 | MEDIUM | 5.5 | 0.2% | Jan 13, 2023 | An Access of Uninitialized Pointer vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and J... |
| CVE-2023-22397 | MEDIUM | 6.1 | 0.2% | Jan 13, 2023 | An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engin... |
| CVE-2023-22395 | MEDIUM | 6.5 | 0.3% | Jan 13, 2023 | A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an ... |
| CVE-2023-22597 | MEDIUM | 5.9 | 0.5% | Jan 12, 2023 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r... |
| CVE-2023-0258 | MEDIUM | 6.1 | 0.4% | Jan 12, 2023 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been rated as problematic. Affected ... |
| CVE-2023-22488 | MEDIUM | 5.4 | 0.4% | Jan 12, 2023 | Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private co... |
| CVE-2023-23457 | MEDIUM | 5.5 | 0.3% | Jan 12, 2023 | A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted... |
| CVE-2023-23456 | MEDIUM | 5.5 | 0.4% | Jan 12, 2023 | A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attack... |
| CVE-2023-0254 | MEDIUM | 4.9 | 0.9% | Jan 12, 2023 | The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in ... |
| CVE-2023-0246 | MEDIUM | 5.4 | 0.6% | Jan 12, 2023 | A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown f... |
| CVE-2023-23455 | MEDIUM | 5.5 | 0.3% | Jan 12, 2023 | atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service be... |
| CVE-2023-23454 | MEDIUM | 5.5 | 0.3% | Jan 12, 2023 | cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (sla... |
| CVE-2023-0042 | MEDIUM | 6.1 | 0.4% | Jan 12, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15... |
| CVE-2023-0227 | MEDIUM | 6.5 | 0.7% | Jan 12, 2023 | Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36. |
| CVE-2023-22492 | MEDIUM | 5.9 | 0.6% | Jan 11, 2023 | ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrie... |
| CVE-2023-22487 | MEDIUM | 4.3 | 0.7% | Jan 11, 2023 | Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extensio... |
| CVE-2023-20532 | MEDIUM | 5.3 | 0.6% | Jan 11, 2023 | Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a ... |
| CVE-2023-20527 | MEDIUM | 6.5 | 0.6% | Jan 11, 2023 | Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, po... |
| CVE-2023-20525 | MEDIUM | 6.5 | 0.6% | Jan 11, 2023 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the b... |
| CVE-2023-20523 | MEDIUM | 5.7 | 0.2% | Jan 11, 2023 | TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of inte... |
| CVE-2023-22963 | MEDIUM | 5.3 | 0.5% | Jan 11, 2023 | The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-... |
| CVE-2023-22958 | MEDIUM | 6.1 | 0.4% | Jan 11, 2023 | The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet... |
| CVE-2023-22945 | MEDIUM | 4.3 | 0.5% | Jan 11, 2023 | In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (bloc... |
| CVE-2023-21776 | MEDIUM | 5.5 | 1.0% | Jan 10, 2023 | Windows Kernel Information Disclosure Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now