2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38688 | HIGH | 7.5 | 0.4% | Aug 4, 2023 | twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication... |
| CVE-2023-38964 | MEDIUM | 6.1 | 1.1% | Aug 4, 2023 | Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2023-38686 | MEDIUM | 5.3 | 0.2% | Aug 4, 2023 | Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email... |
| CVE-2023-38497 | HIGH | 7.3 | 0.8% | Aug 4, 2023 | Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Ru... |
| CVE-2023-38494 | HIGH | 7.5 | 0.4% | Aug 4, 2023 | MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud ver... |
| CVE-2023-38487 | HIGH | 8.2 | 0.7% | Aug 4, 2023 | HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 ... |
| CVE-2023-37896 | HIGH | 7.5 | 0.9% | Aug 4, 2023 | Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizi... |
| CVE-2023-37470 | CRITICAL | 9.8 | 1.1% | Aug 4, 2023 | Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,... |
| CVE-2023-36480 | CRITICAL | 9.8 | 1.7% | Aug 4, 2023 | The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike serv... |
| CVE-2023-29689 | CRITICAL | 9.8 | 41.1% | Aug 4, 2023 | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in... |
| CVE-2023-29505 | HIGH | 8.8 | 0.9% | Aug 4, 2023 | An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross... |
| CVE-2023-4135 | MEDIUM | 6.5 | 0.4% | Aug 4, 2023 | A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate a... |
| CVE-2023-34038 | MEDIUM | 5.3 | 0.4% | Aug 4, 2023 | VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be abl... |
| CVE-2023-34037 | MEDIUM | 5.3 | 0.4% | Aug 4, 2023 | VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able... |
| CVE-2023-39379 | HIGH | 7.5 | 0.4% | Aug 4, 2023 | Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) i... |
| CVE-2023-4142 | HIGH | 8.8 | 1.2% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin... |
| CVE-2023-4141 | HIGH | 8.8 | 1.2% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin... |
| CVE-2023-4140 | HIGH | 8.8 | 0.6% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including... |
| CVE-2023-4139 | HIGH | 7.5 | 0.6% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing... |
| CVE-2023-4002 | MEDIUM | 6.5 | 0.5% | Aug 4, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting... |
| CVE-2023-39343 | MEDIUM | 4.3 | 0.5% | Aug 4, 2023 | Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form... |
| CVE-2023-38708 | HIGH | 8.8 | 0.5% | Aug 4, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path ... |
| CVE-2023-30146 | HIGH | 7.5 | 0.6% | Aug 4, 2023 | Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy o... |
| CVE-2023-3373 | CRITICAL | 9.1 | 0.8% | Aug 4, 2023 | Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model ... |
| CVE-2023-38991 | MEDIUM | 5.4 | 0.4% | Aug 4, 2023 | An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now