2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26239MEDIUM5.5An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible...
CVE-2023-26238MEDIUM5.5An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by se...
CVE-2023-26237MEDIUM6.7An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a ...
CVE-2023-26236HIGH7.8An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGu...
CVE-2023-43877MEDIUM4.8Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ...
CVE-2023-43321HIGH8.8File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbi...
CVE-2023-40299HIGH7.8Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC p...
CVE-2023-35803CRITICAL9.8IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
CVE-2023-44389MEDIUM4.8Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store ...
CVE-2023-43809HIGH7.5Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft ...
CVE-2023-43805HIGH7.5Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete ...
CVE-2023-43799HIGH7.8Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize exte...
CVE-2023-43793HIGH7.5Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user ca...
CVE-2023-41094CRITICAL9.8TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Re...
CVE-2023-36619CRITICAL9.8Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauth...
CVE-2023-36618HIGH8.8Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-...
CVE-2023-44210MEDIUM5.5Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr...
CVE-2023-44209HIGH7.8Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2023-44075MEDIUM5.4Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a cr...
CVE-2023-42809HIGH8.8Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received fr...
CVE-2023-42808MEDIUM6.1Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create publ...
CVE-2023-42449HIGH8.1Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head in...
CVE-2023-38538MEDIUM5A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could ha...
CVE-2023-38537MEDIUM5.6A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incomi...
CVE-2023-5399CRITICAL9.8 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now