2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35082CRITICAL9.8An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu...
CVE-2023-32006HIGH8.8The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the polic...
CVE-2023-32004HIGH8.8A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f...
CVE-2023-32003MEDIUM5.3`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. Th...
CVE-2023-4371MEDIUM6.1A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown fu...
CVE-2023-28479HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain wi...
CVE-2023-30778MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry ...
CVE-2023-30747MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGem WooCommerce Easy Duplicate Product plugin <= 0.3.0.0...
CVE-2023-30498MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 v...
CVE-2023-24478MEDIUM5.5Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro ...
CVE-2023-2916MEDIUM5.3The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ...
CVE-2023-4308MEDIUM5.4The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-conte...
CVE-2023-4347MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
CVE-2023-32358HIGH8.8A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventur...
CVE-2023-28199MEDIUM5.5An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input ...
CVE-2023-28198HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, m...
CVE-2023-28179HIGH7.1The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a malicious...
CVE-2023-27948MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-27947MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-27939MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processin...
CVE-2023-40518HIGH7.5LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
CVE-2023-35689HIGH7.8In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion d...
CVE-2023-21292MEDIUM5.5In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted fil...
CVE-2023-21290MEDIUM5.5In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This co...
CVE-2023-21289MEDIUM5.5In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now