2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34236MEDIUM6.5Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in...
CVE-2023-37473HIGH8.8zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie...
CVE-2023-37472MEDIUM6.5Knowage is an open source suite for business analytics. The application often use user supplied data to create HQL queri...
CVE-2023-37464HIGH7.5OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption ro...
CVE-2023-37462HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escapi...
CVE-2023-3633HIGH7.5An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bi...
CVE-2023-38325HIGH7.5The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVE-2023-37474HIGH7.5Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in t...
CVE-2023-36850MEDIUM6.5An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Manageme...
CVE-2023-38253MEDIUM5.5An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker...
CVE-2023-38252MEDIUM5.5An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to c...
CVE-2023-37224MEDIUM5.5An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain se...
CVE-2023-37223MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a ...
CVE-2023-36888MEDIUM6.3Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVE-2023-36887HIGH7.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2023-36883MEDIUM4.3Microsoft Edge for iOS Spoofing Vulnerability
CVE-2023-36849MEDIUM6.5An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of...
CVE-2023-36848MEDIUM6.5An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networ...
CVE-2023-36840MEDIUM5.5A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved a...
CVE-2023-36836MEDIUM4.7A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J...
CVE-2023-36835HIGH7.5An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N...
CVE-2023-36834MEDIUM6.5An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos O...
CVE-2023-32761HIGH8Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 al...
CVE-2023-32760MEDIUM6.5An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain se...
CVE-2023-32759MEDIUM6.5An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain se...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now