2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21636HIGH7.8Memory Corruption due to improper validation of array index in Linux while updating adn record.
CVE-2023-4748HIGH7.5A vulnerability, which was classified as critical, has been found in Yongyou UFIDA-NC up to 20230807. This issue affects...
CVE-2023-36307MEDIUM5.5ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField ...
CVE-2023-40937Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-40936Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36308MEDIUM5.5disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Graysc...
CVE-2023-4636MEDIUM4.8The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i...
CVE-2023-35906HIGH7.5IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-...
CVE-2023-29261MEDIUM5.5IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain ...
CVE-2023-22870MEDIUM5.9IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in...
CVE-2023-35892CRITICAL9.1IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attac...
CVE-2023-32338MEDIUM5.5IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in pla...
CVE-2023-41058HIGH7.5Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked ...
CVE-2023-3995Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ...
CVE-2023-41057MEDIUM5.5hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern...
CVE-2023-41055HIGH7.5LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subjec...
CVE-2023-41054CRITICAL9.1LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subjec...
CVE-2023-41052MEDIUM5.3Vyper is a Pythonic Smart Contract Language. In affected versions the order of evaluation of the arguments of the builti...
CVE-2023-40015MEDIUM5.3Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compil...
CVE-2023-4758MEDIUM5.5Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-28072HIGH7.8 Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A...
CVE-2023-4755MEDIUM5.5Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4752HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2023-4750HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.1857.
CVE-2023-4733HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now