2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39129 | MEDIUM | 5.5 | 0.2% | Jul 25, 2023 | GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym(... |
| CVE-2023-39128 | MEDIUM | 5.5 | 0.3% | Jul 25, 2023 | GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-la... |
| CVE-2023-36826 | MEDIUM | 6.5 | 0.5% | Jul 25, 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2,... |
| CVE-2023-36806 | MEDIUM | 5.4 | 0.5% | Jul 25, 2023 | Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and... |
| CVE-2023-35982 | CRITICAL | 9.8 | 1.6% | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code... |
| CVE-2023-35981 | CRITICAL | 9.8 | 1.6% | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code... |
| CVE-2023-35980 | CRITICAL | 9.8 | 1.6% | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code... |
| CVE-2023-35944 | MEDIUM | 5.3 | 0.6% | Jul 25, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes i... |
| CVE-2023-35943 | HIGH | 7.5 | 0.6% | Jul 25, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,... |
| CVE-2023-35942 | MEDIUM | 6.5 | 0.7% | Jul 25, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,... |
| CVE-2023-35941 | CRITICAL | 9.8 | 0.7% | Jul 25, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,... |
| CVE-2023-35929 | MEDIUM | 5.4 | 0.4% | Jul 25, 2023 | Tuleap is a free and open source suite to improve management of software development and collaboration. Prior to version... |
| CVE-2023-34235 | HIGH | 7.5 | 0.9% | Jul 25, 2023 | Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fie... |
| CVE-2023-2626 | HIGH | 8.8 | 0.1% | Jul 25, 2023 | There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue ... |
| CVE-2023-3773 | MEDIUM | 4.4 | 0.2% | Jul 25, 2023 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma... |
| CVE-2023-3772 | MEDIUM | 4.4 | 0.5% | Jul 25, 2023 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma... |
| CVE-2023-38435 | MEDIUM | 6.1 | 1.8% | Jul 25, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache... |
| CVE-2023-39175 | MEDIUM | 6.1 | 0.9% | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible |
| CVE-2023-39174 | HIGH | 7.5 | 1.4% | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers |
| CVE-2023-39173 | HIGH | 8.8 | 0.3% | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access |
| CVE-2023-37895 | CRITICAL | 9.8 | 2.7% | Jul 25, 2023 | Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute c... |
| CVE-2023-34093 | HIGH | 7.1 | 0.6% | Jul 25, 2023 | Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, ... |
| CVE-2023-3548 | CRITICAL | 9.8 | 0.4% | Jul 25, 2023 | An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authenti... |
| CVE-2023-36503 | MEDIUM | 5.4 | 0.3% | Jul 25, 2023 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <... |
| CVE-2023-36502 | MEDIUM | 6.1 | 0.4% | Jul 25, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now