2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39129MEDIUM5.5GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym(...
CVE-2023-39128MEDIUM5.5GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-la...
CVE-2023-36826MEDIUM6.5Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2,...
CVE-2023-36806MEDIUM5.4Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and...
CVE-2023-35982CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35981CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35980CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35944MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes i...
CVE-2023-35943HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,...
CVE-2023-35942MEDIUM6.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,...
CVE-2023-35941CRITICAL9.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,...
CVE-2023-35929MEDIUM5.4Tuleap is a free and open source suite to improve management of software development and collaboration. Prior to version...
CVE-2023-34235HIGH7.5Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fie...
CVE-2023-2626HIGH8.8There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue ...
CVE-2023-3773MEDIUM4.4A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma...
CVE-2023-3772MEDIUM4.4A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma...
CVE-2023-38435MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache...
CVE-2023-39175MEDIUM6.1In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
CVE-2023-39174HIGH7.5In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
CVE-2023-39173HIGH8.8In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
CVE-2023-37895CRITICAL9.8Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute c...
CVE-2023-34093HIGH7.1Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, ...
CVE-2023-3548CRITICAL9.8An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authenti...
CVE-2023-36503MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <...
CVE-2023-36502MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now