2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36468 | HIGH | 8.8 | 1.6% | Jun 29, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki i... |
| CVE-2023-36471 | MEDIUM | 5.4 | 0.9% | Jun 29, 2023 | Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki... |
| CVE-2023-35938 | HIGH | 7.2 | 0.5% | Jun 29, 2023 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching f... |
| CVE-2023-26966 | MEDIUM | 5.5 | 0.4% | Jun 29, 2023 | libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and... |
| CVE-2023-25433 | MEDIUM | 5.5 | 0.4% | Jun 29, 2023 | libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size aft... |
| CVE-2023-36484 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS). |
| CVE-2023-33190 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior... |
| CVE-2023-30955 | MEDIUM | 5.4 | 0.3% | Jun 29, 2023 | A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and vi... |
| CVE-2023-30946 | MEDIUM | 4.3 | 0.3% | Jun 29, 2023 | A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have... |
| CVE-2023-36488 | MEDIUM | 5.4 | 0.3% | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS). |
| CVE-2023-36487 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take ov... |
| CVE-2023-34658 | MEDIUM | 5.3 | 0.4% | Jun 29, 2023 | Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSa... |
| CVE-2023-26085 | HIGH | 7.8 | 0.3% | Jun 29, 2023 | A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Andr... |
| CVE-2023-37256 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in ... |
| CVE-2023-37255 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "g... |
| CVE-2023-37254 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a c... |
| CVE-2023-37251 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackur... |
| CVE-2023-35830 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.0... |
| CVE-2023-33277 | HIGH | 7.5 | 1.0% | Jun 29, 2023 | The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitiv... |
| CVE-2023-31222 | HIGH | 8.8 | 25.8% | Jun 29, 2023 | Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and... |
| CVE-2023-26616 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in Set... |
| CVE-2023-26613 | CRITICAL | 9.8 | 29.1% | Jun 29, 2023 | An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execu... |
| CVE-2023-26612 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field i... |
| CVE-2023-34849 | CRITICAL | 9.8 | 2.6% | Jun 29, 2023 | An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai route... |
| CVE-2023-34844 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now