2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3829 | MEDIUM | 6.1 | 0.3% | Jul 22, 2023 | A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects un... |
| CVE-2023-3828 | MEDIUM | 6.1 | 0.3% | Jul 22, 2023 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic.... |
| CVE-2023-3827 | MEDIUM | 6.1 | 0.3% | Jul 22, 2023 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected... |
| CVE-2023-3826 | CRITICAL | 9.8 | 0.6% | Jul 22, 2023 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. Affected by this vulnerability is an unknown... |
| CVE-2023-3247 | MEDIUM | 4.3 | 0.7% | Jul 22, 2023 | In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication,... |
| CVE-2023-28530 | MEDIUM | 5.4 | 0.5% | Jul 22, 2023 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Fi... |
| CVE-2023-25929 | MEDIUM | 5.4 | 0.4% | Jul 22, 2023 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2023-3776 | HIGH | 7.8 | 0.5% | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi... |
| CVE-2023-3611 | HIGH | 7.8 | 0.3% | Jul 21, 2023 | An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve loca... |
| CVE-2023-3610 | HIGH | 7.8 | 0.3% | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-3609 | HIGH | 7.8 | 0.4% | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv... |
| CVE-2023-37918 | HIGH | 7.5 | 1.1% | Jul 21, 2023 | Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability h... |
| CVE-2023-37917 | HIGH | 8.8 | 0.6% | Jul 21, 2023 | KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can becom... |
| CVE-2023-37916 | HIGH | 7.5 | 0.7% | Jul 21, 2023 | KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 lea... |
| CVE-2023-37915 | HIGH | 7.5 | 0.8% | Jul 21, 2023 | OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenD... |
| CVE-2023-35077 | HIGH | 7.5 | 1.5% | Jul 21, 2023 | An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update t... |
| CVE-2023-3603 | MEDIUM | 6.5 | 0.8% | Jul 21, 2023 | A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions... |
| CVE-2023-37905 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wor... |
| CVE-2023-37903 | CRITICAL | 10 | 2.8% | Jul 21, 2023 | vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect fun... |
| CVE-2023-36339 | HIGH | 7.5 | 0.5% | Jul 21, 2023 | An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET ... |
| CVE-2023-37901 | MEDIUM | 5.4 | 0.4% | Jul 21, 2023 | Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerabili... |
| CVE-2023-25841 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux ... |
| CVE-2023-25840 | LOW | 3.4 | 0.4% | Jul 21, 2023 | There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe... |
| CVE-2023-38187 | MEDIUM | 6.5 | 0.7% | Jul 21, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-38173 | MEDIUM | 4.3 | 0.6% | Jul 21, 2023 | Microsoft Edge for Android Spoofing Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now