2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41329MEDIUM6.6WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions c...
CVE-2023-41327MEDIUM5.4WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recordin...
CVE-2023-41053LOW3.3Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and a...
CVE-2023-40397CRITICAL9.8The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able t...
CVE-2023-40392LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura...
CVE-2023-39967CRITICAL10WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Stud...
CVE-2023-39956MEDIUM6.6Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro...
CVE-2023-38616HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13.5. An app may be ab...
CVE-2023-38605LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.5. An...
CVE-2023-29198HIGH8.5Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro...
CVE-2023-23623CRITICAL9.8Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Conte...
CVE-2023-4809HIGH7.5In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers woul...
CVE-2023-41601MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute ar...
CVE-2023-40591HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made t...
CVE-2023-41330CRITICAL9.8knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue ...
CVE-2023-41328HIGH7.5Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified i...
CVE-2023-41319HIGH7.2Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ...
CVE-2023-41050HIGH7.7AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone cont...
CVE-2023-39511MEDIUM4.8Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored...
CVE-2023-38486MEDIUM6.4A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows...
CVE-2023-38485MEDIUM6.4Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow...
CVE-2023-38484MEDIUM6.4Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow...
CVE-2023-20269CRITICAL9.1A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower...
CVE-2023-20263MEDIUM6.1A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated...
CVE-2023-20243HIGH8.6A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now