2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0462CRITICAL9.1An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on t...
CVE-2023-0118CRITICAL9.1An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates a...
CVE-2023-4236HIGH7.5A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assert...
CVE-2023-43477HIGH8.8The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware vers...
CVE-2023-3341HIGH7.5The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsi...
CVE-2023-0829CRITICAL9Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a cu...
CVE-2023-5042HIGH7.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ...
CVE-2023-5084MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
CVE-2023-4853HIGH8.1A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly whe...
CVE-2023-34047MEDIUM4.3A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context...
CVE-2023-41375HIGH7.8Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed ...
CVE-2023-41374HIGH7.8Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed...
CVE-2023-22644MEDIUM5.5A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ...
CVE-2023-43621MEDIUM4.7An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users ...
CVE-2023-43620HIGH7.8An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack t...
CVE-2023-43619HIGH7.8An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable c...
CVE-2023-43618MEDIUM5.3An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in clear...
CVE-2023-43617MEDIUM5.3An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge ...
CVE-2023-43616MEDIUM5.5An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
CVE-2023-2163HIGH8.8Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, res...
CVE-2023-26144MEDIUM5.3Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insuffici...
CVE-2023-5063MEDIUM5.4The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortc...
CVE-2023-5062MEDIUM5.4The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in vers...
CVE-2023-4088HIGH7.8Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products...
CVE-2023-31015HIGH7.8NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now