2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33364 | HIGH | 8.8 | 1.5% | Aug 3, 2023 | An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to exe... |
| CVE-2023-33363 | HIGH | 7.5 | 0.6% | Aug 3, 2023 | An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to a... |
| CVE-2023-4138 | MEDIUM | 6.5 | 0.4% | Aug 3, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0. |
| CVE-2023-4136 | MEDIUM | 6.1 | 1.3% | Aug 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine ... |
| CVE-2023-4133 | MEDIUM | 5.5 | 0.2% | Aug 3, 2023 | A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device i... |
| CVE-2023-4132 | MEDIUM | 5.5 | 0.3% | Aug 3, 2023 | A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device in... |
| CVE-2023-3766 | MEDIUM | 5.9 | 0.7% | Aug 3, 2023 | A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted qu... |
| CVE-2023-3348 | MEDIUM | 5.7 | 0.7% | Aug 3, 2023 | The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerabil... |
| CVE-2023-3180 | MEDIUM | 6.5 | 0.2% | Aug 3, 2023 | A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_h... |
| CVE-2023-39097 | MEDIUM | 5.4 | 0.3% | Aug 3, 2023 | WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability. |
| CVE-2023-39096 | MEDIUM | 5.4 | 0.3% | Aug 3, 2023 | WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and o... |
| CVE-2023-38812 | — | — | — | Aug 3, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-36299 | HIGH | 8.8 | 1.4% | Aug 3, 2023 | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and opt... |
| CVE-2023-36298 | HIGH | 8.8 | 1.2% | Aug 3, 2023 | DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). |
| CVE-2023-2754 | MEDIUM | 6.8 | 0.7% | Aug 3, 2023 | The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS... |
| CVE-2023-28468 | MEDIUM | 6.5 | 0.2% | Aug 3, 2023 | An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntime... |
| CVE-2023-25600 | HIGH | 7.1 | 0.2% | Aug 3, 2023 | An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, lead... |
| CVE-2023-22277 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-22317 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-22314 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-3669 | LOW | 3.3 | 0.1% | Aug 3, 2023 | A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimi... |
| CVE-2023-37559 | MEDIUM | 6.5 | 0.5% | Aug 3, 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co... |
| CVE-2023-37558 | MEDIUM | 6.5 | 0.5% | Aug 3, 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co... |
| CVE-2023-37557 | MEDIUM | 6.5 | 0.5% | Aug 3, 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote com... |
| CVE-2023-37556 | MEDIUM | 6.5 | 0.5% | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now