2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5391CRITICAL9.8 A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary c...
CVE-2023-42824HIGH7.8The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may ...
CVE-2023-42448HIGH8.1Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont...
CVE-2023-3576MEDIUM5.5A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image fil...
CVE-2023-3428MEDIUM5.5A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local atta...
CVE-2023-39191HIGH8.2An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of...
CVE-2023-38701CRITICAL9.1Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to co...
CVE-2023-27121MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasa...
CVE-2023-5402CRITICAL9.8 A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the trans...
CVE-2023-5371MEDIUM6.5RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection...
CVE-2023-43804HIGH8.1urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or pro...
CVE-2023-20259HIGH7.5A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, rem...
CVE-2023-20235HIGH8.8A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr...
CVE-2023-20101CRITICAL9.8A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected de...
CVE-2023-43838HIGH7.8An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code ...
CVE-2023-5113MEDIUM6.1Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to W...
CVE-2023-4380MEDIUM6.3A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, th...
CVE-2023-4237HIGH7.8A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the priv...
CVE-2023-40559HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin...
CVE-2023-3971MEDIUM5.4An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture c...
CVE-2023-3665HIGH7.8 A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable th...
CVE-2023-5374CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by thi...
CVE-2023-4567Rejected reason: Issue has been found to be non-reproducible, therefore not a viable flaw.
CVE-2023-40684MEDIUM5.4IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. T...
CVE-2023-40561HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now