2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36468HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki i...
CVE-2023-36471MEDIUM5.4Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki...
CVE-2023-35938HIGH7.2 Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching f...
CVE-2023-26966MEDIUM5.5libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and...
CVE-2023-25433MEDIUM5.5libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size aft...
CVE-2023-36484MEDIUM6.1ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
CVE-2023-33190CRITICAL9.8Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior...
CVE-2023-30955MEDIUM5.4A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and vi...
CVE-2023-30946MEDIUM4.3A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have...
CVE-2023-36488MEDIUM5.4ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
CVE-2023-36487CRITICAL9.8The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take ov...
CVE-2023-34658MEDIUM5.3Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSa...
CVE-2023-26085HIGH7.8A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Andr...
CVE-2023-37256MEDIUM6.1An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in ...
CVE-2023-37255MEDIUM6.1An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "g...
CVE-2023-37254MEDIUM6.1An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a c...
CVE-2023-37251MEDIUM6.1An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackur...
CVE-2023-35830CRITICAL9.8STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.0...
CVE-2023-33277HIGH7.5The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitiv...
CVE-2023-31222HIGH8.8Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and...
CVE-2023-26616CRITICAL9.8D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in Set...
CVE-2023-26613CRITICAL9.8An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execu...
CVE-2023-26612CRITICAL9.8D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field i...
CVE-2023-34849CRITICAL9.8An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai route...
CVE-2023-34844CRITICAL9.8Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now