2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40035 | HIGH | 7.2 | 1.9% | Aug 23, 2023 | Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can le... |
| CVE-2023-40176 | MEDIUM | 5.4 | 78.9% | Aug 23, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered ... |
| CVE-2023-40025 | HIGH | 7.1 | 0.5% | Aug 23, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version ... |
| CVE-2023-40612 | HIGH | 8 | 0.4% | Aug 23, 2023 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FI... |
| CVE-2023-20234 | MEDIUM | 6 | 0.2% | Aug 23, 2023 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overw... |
| CVE-2023-20230 | MEDIUM | 5.4 | 0.3% | Aug 23, 2023 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (... |
| CVE-2023-20200 | MEDIUM | 6.3 | 0.5% | Aug 23, 2023 | A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Serie... |
| CVE-2023-20169 | HIGH | 7.4 | 0.3% | Aug 23, 2023 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco... |
| CVE-2023-20168 | MEDIUM | 6.5 | 0.2% | Aug 23, 2023 | A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc... |
| CVE-2023-20115 | MEDIUM | 5.4 | 0.4% | Aug 23, 2023 | A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in stand... |
| CVE-2023-40270 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-38831. Reason: This candidate is a reservation d... |
| CVE-2023-39583 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-38831. Reason: This candidate is a reservation d... |
| CVE-2023-38831 | HIGH | 7.8 | 97.8% | Aug 23, 2023 | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a... |
| CVE-2023-40273 | HIGH | 8 | 1.4% | Aug 23, 2023 | The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the... |
| CVE-2023-39441 | MEDIUM | 5.9 | 0.6% | Aug 23, 2023 | Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 ar... |
| CVE-2023-37379 | HIGH | 8.1 | 1.5% | Aug 23, 2023 | Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated ... |
| CVE-2023-1409 | HIGH | 7.5 | 0.4% | Aug 23, 2023 | If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options ... |
| CVE-2023-41126 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41125 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41124 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41123 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41122 | — | — | — | Aug 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-32509 | MEDIUM | 6.1 | 0.4% | Aug 23, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 ... |
| CVE-2023-32505 | MEDIUM | 4.8 | 0.4% | Aug 23, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions. |
| CVE-2023-32300 | MEDIUM | 6.1 | 0.4% | Aug 23, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now