2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38700 | LOW | 3.7 | 0.5% | Aug 4, 2023 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such... |
| CVE-2023-4159 | HIGH | 8.8 | 0.8% | Aug 4, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3. |
| CVE-2023-4158 | MEDIUM | 5.4 | 0.4% | Aug 4, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3. |
| CVE-2023-4157 | MEDIUM | 4.8 | 0.4% | Aug 4, 2023 | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repo... |
| CVE-2023-39107 | CRITICAL | 9.1 | 1.0% | Aug 4, 2023 | An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows... |
| CVE-2023-38699 | MEDIUM | 6.5 | 0.2% | Aug 4, 2023 | MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0,... |
| CVE-2023-38698 | MEDIUM | 6.5 | 0.7% | Aug 4, 2023 | Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. Accor... |
| CVE-2023-38697 | MEDIUM | 5.3 | 0.6% | Aug 4, 2023 | protocol-http1 provides a low-level implementation of the HTTP/1 protocol. RFC 9112 Section 7.1 defined the format of ch... |
| CVE-2023-38695 | MEDIUM | 6.5 | 0.8% | Aug 4, 2023 | cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possib... |
| CVE-2023-38692 | CRITICAL | 9.8 | 2.8% | Aug 4, 2023 | CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command i... |
| CVE-2023-38332 | MEDIUM | 6.5 | 3.0% | Aug 4, 2023 | Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitiv... |
| CVE-2023-33379 | CRITICAL | 9.8 | 0.7% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, ... |
| CVE-2023-33378 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro... |
| CVE-2023-33377 | CRITICAL | 9.8 | 1.5% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its commu... |
| CVE-2023-33376 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati... |
| CVE-2023-33375 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling at... |
| CVE-2023-33374 | CRITICAL | 9.8 | 1.3% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to sp... |
| CVE-2023-33373 | CRITICAL | 9.8 | 0.4% | Aug 4, 2023 | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the... |
| CVE-2023-33372 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi... |
| CVE-2023-0264 | MEDIUM | 5 | 1.3% | Aug 4, 2023 | A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authen... |
| CVE-2023-39143 | CRITICAL | 9.8 | 78.7% | Aug 4, 2023 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete... |
| CVE-2023-39112 | MEDIUM | 6.5 | 0.6% | Aug 4, 2023 | ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel. |
| CVE-2023-38691 | MEDIUM | 6.5 | 0.4% | Aug 4, 2023 | matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 a... |
| CVE-2023-38690 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with... |
| CVE-2023-38689 | CRITICAL | 9.8 | 1.2% | Aug 4, 2023 | Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `Object... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now