2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1401MEDIUM4.3An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which t...
CVE-2023-3946MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated a...
CVE-2023-20891MEDIUM6.5The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due t...
CVE-2023-3947MEDIUM5.3The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded e...
CVE-2023-32629HIGH7.8Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks ...
CVE-2023-2640HIGH7.8On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay...
CVE-2023-38503MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to...
CVE-2023-3945MEDIUM6.1A vulnerability was found in phpscriptpoint Lawyer 1.6. It has been classified as problematic. This affects an unknown p...
CVE-2023-38502MEDIUM6.5TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDe...
CVE-2023-38501MEDIUM6.1copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via...
CVE-2023-38496LOW3.3Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when request...
CVE-2023-38500MEDIUM6.1TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on e...
CVE-2023-38499MEDIUM5.3TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ...
CVE-2023-38493HIGH7.5Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spr...
CVE-2023-37920CRITICAL9.8Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify...
CVE-2023-37919MEDIUM5.4Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain ...
CVE-2023-37907HIGH7.8Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI in...
CVE-2023-37902MEDIUM5.3Vyper is a Pythonic programming language that targets the Ethereum Virtual Machine (EVM). Prior to version 0.3.10, the e...
CVE-2023-3944MEDIUM6.1A vulnerability was found in phpscriptpoint Lawyer 1.6 and classified as problematic. Affected by this issue is some unk...
CVE-2023-37677CRITICAL9.8Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the com...
CVE-2023-37460CRITICAL9.8Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unifie...
CVE-2023-37258CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulne...
CVE-2023-37257MEDIUM5.4DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset hav...
CVE-2023-34798CRITICAL9.8An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a...
CVE-2023-39130MEDIUM5.5GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now