2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4349HIGH8.8Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potential...
CVE-2023-4345MEDIUM6.5Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for lo...
CVE-2023-40028MEDIUM6.5Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows ...
CVE-2023-40027MEDIUM5.3Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as ...
CVE-2023-2312HIGH8.8Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromis...
CVE-2023-39662CRITICAL9.8An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter ...
CVE-2023-39661CRITICAL9.8An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak functi...
CVE-2023-39659CRITICAL9.8An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted...
CVE-2023-39438HIGH8.1A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CL...
CVE-2023-38916HIGH8.8SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sen...
CVE-2023-38915CRITICAL9.8File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload...
CVE-2023-38898MEDIUM5.3An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task ...
CVE-2023-38896CRITICAL9.8An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the fro...
CVE-2023-38889CRITICAL9.8An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username...
CVE-2023-38860CRITICAL9.8An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
CVE-2023-38858MEDIUM6.5Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38857MEDIUM5.5Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38856MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38855MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38854MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38853MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38852MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38851MEDIUM6.5Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of ...
CVE-2023-38850MEDIUM5.5Buffer Overflow vulnerability in Michaelrsweet codedoc v.3.7 allows an attacker to cause a denial of service via the cod...
CVE-2023-38840MEDIUM5.5Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwar...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now