2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3829MEDIUM6.1A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects un...
CVE-2023-3828MEDIUM6.1A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic....
CVE-2023-3827MEDIUM6.1A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected...
CVE-2023-3826CRITICAL9.8A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. Affected by this vulnerability is an unknown...
CVE-2023-3247MEDIUM4.3In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication,...
CVE-2023-28530MEDIUM5.4IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Fi...
CVE-2023-25929MEDIUM5.4IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2023-3776HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi...
CVE-2023-3611HIGH7.8An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve loca...
CVE-2023-3610HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-3609HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv...
CVE-2023-37918HIGH7.5Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability h...
CVE-2023-37917HIGH8.8KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can becom...
CVE-2023-37916HIGH7.5KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 lea...
CVE-2023-37915HIGH7.5OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenD...
CVE-2023-35077HIGH7.5An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update t...
CVE-2023-3603MEDIUM6.5A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions...
CVE-2023-37905MEDIUM6.1ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wor...
CVE-2023-37903CRITICAL10vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect fun...
CVE-2023-36339HIGH7.5An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET ...
CVE-2023-37901MEDIUM5.4Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerabili...
CVE-2023-25841MEDIUM6.1There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux ...
CVE-2023-25840LOW3.4There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe...
CVE-2023-38187MEDIUM6.5Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-38173MEDIUM4.3Microsoft Edge for Android Spoofing Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now