2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36735CRITICAL9.6Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-36727MEDIUM6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-36562HIGH7.1Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-42442MEDIUM5.3JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting i...
CVE-2023-42439MEDIUM6.5GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A S...
CVE-2023-41901Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2023-41900MEDIUM4.3Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable...
CVE-2023-41889MEDIUM5.3SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalizati...
CVE-2023-41887CRITICAL9.8OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execu...
CVE-2023-41886HIGH7.5OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file r...
CVE-2023-0923CRITICAL9.8A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces ...
CVE-2023-0813HIGH7.5A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is s...
CVE-2023-41880MEDIUM5.3Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 co...
CVE-2023-41325MEDIUM6.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2023-41043MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-41042MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-40588MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-40167MEDIUM5.3Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accep...
CVE-2023-40019MEDIUM6.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-40018HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-38706MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o...
CVE-2023-38507CRITICAL9.8Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the l...
CVE-2023-37459MEDIUM5.3Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, ...
CVE-2023-37281MEDIUM5.3Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various...
CVE-2023-37263LOW2.7Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are no...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now