2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36816MEDIUM6.12FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site script...
CVE-2023-36814HIGH7.5Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's mar...
CVE-2023-35935Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-31999. Reason: This candidate is a ...
CVE-2023-34451HIGH8.2CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many ...
CVE-2023-34450MEDIUM5.3CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many ...
CVE-2023-26509HIGH7.5AnyDesk 7.0.8 allows remote Denial of Service.
CVE-2023-26258CRITICAL9.8Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe...
CVE-2023-36053HIGH7.5In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a pot...
CVE-2023-35797CRITICAL9.8Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A...
CVE-2023-3314HIGH8.8 A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutral...
CVE-2023-3438HIGH7.8 An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install servic...
CVE-2023-3313HIGH7.8 An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special element...
CVE-2023-3370Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-36001Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-35999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-35700Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-35073Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-34211Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-26136CRITICAL9.8Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cook...
CVE-2023-31997CRITICAL9UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to acc...
CVE-2023-30589HIGH7.5The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. T...
CVE-2023-30586HIGH7.5A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experi...
CVE-2023-28365CRITICAL9.1A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems ...
CVE-2023-28364MEDIUM6.1An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android ...
CVE-2023-28324CRITICAL9.8A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now