2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1401 | MEDIUM | 4.3 | 0.4% | Jul 26, 2023 | An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which t... |
| CVE-2023-3946 | MEDIUM | 6.1 | 0.5% | Jul 26, 2023 | A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated a... |
| CVE-2023-20891 | MEDIUM | 6.5 | 0.5% | Jul 26, 2023 | The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due t... |
| CVE-2023-3947 | MEDIUM | 5.3 | 0.3% | Jul 26, 2023 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded e... |
| CVE-2023-32629 | HIGH | 7.8 | 8.9% | Jul 26, 2023 | Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks ... |
| CVE-2023-2640 | HIGH | 7.8 | 15.8% | Jul 26, 2023 | On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay... |
| CVE-2023-38503 | MEDIUM | 6.5 | 0.4% | Jul 25, 2023 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to... |
| CVE-2023-3945 | MEDIUM | 6.1 | 0.3% | Jul 25, 2023 | A vulnerability was found in phpscriptpoint Lawyer 1.6. It has been classified as problematic. This affects an unknown p... |
| CVE-2023-38502 | MEDIUM | 6.5 | 0.6% | Jul 25, 2023 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDe... |
| CVE-2023-38501 | MEDIUM | 6.1 | 6.2% | Jul 25, 2023 | copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via... |
| CVE-2023-38496 | LOW | 3.3 | 0.2% | Jul 25, 2023 | Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when request... |
| CVE-2023-38500 | MEDIUM | 6.1 | 0.4% | Jul 25, 2023 | TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on e... |
| CVE-2023-38499 | MEDIUM | 5.3 | 0.9% | Jul 25, 2023 | TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ... |
| CVE-2023-38493 | HIGH | 7.5 | 0.6% | Jul 25, 2023 | Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spr... |
| CVE-2023-37920 | CRITICAL | 9.8 | 0.5% | Jul 25, 2023 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify... |
| CVE-2023-37919 | MEDIUM | 5.4 | 0.3% | Jul 25, 2023 | Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain ... |
| CVE-2023-37907 | HIGH | 7.8 | 0.2% | Jul 25, 2023 | Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI in... |
| CVE-2023-37902 | MEDIUM | 5.3 | 0.5% | Jul 25, 2023 | Vyper is a Pythonic programming language that targets the Ethereum Virtual Machine (EVM). Prior to version 0.3.10, the e... |
| CVE-2023-3944 | MEDIUM | 6.1 | 0.3% | Jul 25, 2023 | A vulnerability was found in phpscriptpoint Lawyer 1.6 and classified as problematic. Affected by this issue is some unk... |
| CVE-2023-37677 | CRITICAL | 9.8 | 1.1% | Jul 25, 2023 | Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the com... |
| CVE-2023-37460 | CRITICAL | 9.8 | 2.1% | Jul 25, 2023 | Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unifie... |
| CVE-2023-37258 | CRITICAL | 9.8 | 0.9% | Jul 25, 2023 | DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulne... |
| CVE-2023-37257 | MEDIUM | 5.4 | 0.4% | Jul 25, 2023 | DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset hav... |
| CVE-2023-34798 | CRITICAL | 9.8 | 0.7% | Jul 25, 2023 | An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a... |
| CVE-2023-39130 | MEDIUM | 5.5 | 0.2% | Jul 25, 2023 | GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now