2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34106MEDIUM6.5GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8...
CVE-2023-33335MEDIUM6.1Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbi...
CVE-2023-30607HIGH8.8icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, t...
CVE-2023-25399MEDIUM5.5A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() f...
CVE-2023-36934CRITICAL9.1In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1....
CVE-2023-36933HIGH7.5In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023....
CVE-2023-36932HIGH8.1In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1....
CVE-2023-31194HIGH7.8An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A sp...
CVE-2023-27390HIGH7.8A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A speciall...
CVE-2023-3515MEDIUM4.4Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
CVE-2023-35979HIGH7.5There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management in...
CVE-2023-35978MEDIUM6.1A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (X...
CVE-2023-35977MEDIUM6.5Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line ...
CVE-2023-35976MEDIUM6.5Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line ...
CVE-2023-35975HIGH8.1An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t...
CVE-2023-35974HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2023-35973HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2023-35972HIGH7.2An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful...
CVE-2023-35971MEDIUM6.1A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct ...
CVE-2023-36665CRITICAL9.8"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than...
CVE-2023-3455CRITICAL9.1Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability an...
CVE-2023-3089HIGH7.5A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was ...
CVE-2023-2538MEDIUM4.2A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 ...
CVE-2023-3482MEDIUM6.5When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using...
CVE-2023-3336MEDIUM5.3TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may all...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now