2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20207MEDIUM6.5A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker...
CVE-2023-20185HIGH7.4A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in AC...
CVE-2023-3596HIGH7.5 Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow...
CVE-2023-3595CRITICAL9.8 Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products,...
CVE-2023-38069LOW3.3In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
CVE-2023-38068HIGH7.3In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
CVE-2023-38067MEDIUM6.5In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
CVE-2023-38066MEDIUM6.1In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
CVE-2023-38065MEDIUM5.4In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
CVE-2023-38064MEDIUM6.5In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
CVE-2023-38063MEDIUM5.4In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
CVE-2023-38062MEDIUM6.5In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite b...
CVE-2023-38061MEDIUM5.4In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
CVE-2023-33668CRITICAL9.8DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts...
CVE-2023-37582CRITICAL9.8The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not...
CVE-2023-37579MEDIUM6.5Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects A...
CVE-2023-36543MEDIUM6.5Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the...
CVE-2023-35908MEDIUM6.5Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG thro...
CVE-2023-31007MEDIUM6.5Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connect...
CVE-2023-30429HIGH8.8Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: be...
CVE-2023-30428HIGH8.1Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenti...
CVE-2023-22888MEDIUM6.5Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disrupt...
CVE-2023-22887MEDIUM6.5Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized fi...
CVE-2023-3106HIGH7.8A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receive...
CVE-2023-33905MEDIUM4.4In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now