2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26115 | HIGH | 7.5 | 1.7% | Jun 22, 2023 | All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of... |
| CVE-2023-33842 | MEDIUM | 5.5 | 0.2% | Jun 22, 2023 | IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server ... |
| CVE-2023-28956 | HIGH | 7.8 | 0.2% | Jun 22, 2023 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges ... |
| CVE-2023-33405 | MEDIUM | 6.1 | 31.3% | Jun 21, 2023 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. |
| CVE-2023-24261 | HIGH | 7.2 | 18.8% | Jun 21, 2023 | A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code ... |
| CVE-2023-3110 | HIGH | 8.8 | 0.4% | Jun 21, 2023 | Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave ... |
| CVE-2023-33591 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnera... |
| CVE-2023-33289 | HIGH | 7.5 | 1.2% | Jun 21, 2023 | The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs... |
| CVE-2023-25435 | MEDIUM | 5.5 | 0.3% | Jun 21, 2023 | libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753. |
| CVE-2023-0972 | HIGH | 8.8 | 0.4% | Jun 21, 2023 | Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave... |
| CVE-2023-0971 | HIGH | 8.8 | 0.3% | Jun 21, 2023 | A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration... |
| CVE-2023-0970 | MEDIUM | 6.8 | 0.3% | Jun 21, 2023 | Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with i... |
| CVE-2023-0969 | LOW | 3.5 | 0.3% | Jun 21, 2023 | A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manip... |
| CVE-2023-2911 | HIGH | 7.5 | 2.6% | Jun 21, 2023 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `st... |
| CVE-2023-2829 | HIGH | 7.5 | 0.9% | Jun 21, 2023 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validat... |
| CVE-2023-2828 | HIGH | 7.5 | 3.8% | Jun 21, 2023 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the... |
| CVE-2023-0026 | HIGH | 7.5 | 0.6% | Jun 21, 2023 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O... |
| CVE-2023-33725 | MEDIUM | 6.1 | 0.5% | Jun 21, 2023 | Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerab... |
| CVE-2023-27243 | HIGH | 7.5 | 0.4% | Jun 21, 2023 | An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a... |
| CVE-2023-27432 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WpSimpleTools Manage Upload Limit plugin <= 1.0.4 versions... |
| CVE-2023-27429 | MEDIUM | 4.8 | 0.4% | Jun 21, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.... |
| CVE-2023-27414 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. |
| CVE-2023-33584 | CRITICAL | 9.8 | 14.2% | Jun 21, 2023 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to ... |
| CVE-2023-27450 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versio... |
| CVE-2023-27443 | MEDIUM | 5.4 | 0.4% | Jun 21, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now