2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36816 | MEDIUM | 6.1 | 0.5% | Jul 3, 2023 | 2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site script... |
| CVE-2023-36814 | HIGH | 7.5 | 0.6% | Jul 3, 2023 | Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's mar... |
| CVE-2023-35935 | — | — | — | Jul 3, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-31999. Reason: This candidate is a ... |
| CVE-2023-34451 | HIGH | 8.2 | 0.7% | Jul 3, 2023 | CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many ... |
| CVE-2023-34450 | MEDIUM | 5.3 | 0.7% | Jul 3, 2023 | CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many ... |
| CVE-2023-26509 | HIGH | 7.5 | 0.8% | Jul 3, 2023 | AnyDesk 7.0.8 allows remote Denial of Service. |
| CVE-2023-26258 | CRITICAL | 9.8 | 34.2% | Jul 3, 2023 | Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe... |
| CVE-2023-36053 | HIGH | 7.5 | 2.7% | Jul 3, 2023 | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a pot... |
| CVE-2023-35797 | CRITICAL | 9.8 | 2.1% | Jul 3, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A... |
| CVE-2023-3314 | HIGH | 8.8 | 0.9% | Jul 3, 2023 | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutral... |
| CVE-2023-3438 | HIGH | 7.8 | 0.2% | Jul 3, 2023 | An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install servic... |
| CVE-2023-3313 | HIGH | 7.8 | 0.5% | Jul 3, 2023 | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special element... |
| CVE-2023-3370 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-36001 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-35999 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-35700 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-35073 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-34211 | — | — | — | Jul 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-26136 | CRITICAL | 9.8 | 2.1% | Jul 1, 2023 | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cook... |
| CVE-2023-31997 | CRITICAL | 9 | 0.2% | Jul 1, 2023 | UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to acc... |
| CVE-2023-30589 | HIGH | 7.5 | 3.9% | Jul 1, 2023 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. T... |
| CVE-2023-30586 | HIGH | 7.5 | 1.3% | Jul 1, 2023 | A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experi... |
| CVE-2023-28365 | CRITICAL | 9.1 | 0.6% | Jul 1, 2023 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems ... |
| CVE-2023-28364 | MEDIUM | 6.1 | 0.4% | Jul 1, 2023 | An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android ... |
| CVE-2023-28324 | CRITICAL | 9.8 | 11.8% | Jul 1, 2023 | A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now