2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3173 | CRITICAL | 9.8 | 1.1% | Jun 9, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20. |
| CVE-2023-3172 | HIGH | 7.2 | 1.2% | Jun 9, 2023 | Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20. |
| CVE-2023-34112 | HIGH | 8.8 | 1.9% | Jun 9, 2023 | JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/java... |
| CVE-2023-34243 | MEDIUM | 5.3 | 0.5% | Jun 8, 2023 | TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgst... |
| CVE-2023-34233 | HIGH | 8.8 | 1.8% | Jun 8, 2023 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak... |
| CVE-2023-34232 | HIGH | 8.8 | 1.9% | Jun 8, 2023 | snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) b... |
| CVE-2023-34230 | HIGH | 8.8 | 1.4% | Jun 8, 2023 | snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 vi... |
| CVE-2023-32751 | MEDIUM | 5.4 | 2.9% | Jun 8, 2023 | Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera... |
| CVE-2023-32750 | MEDIUM | 6.5 | 3.8% | Jun 8, 2023 | Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which ... |
| CVE-2023-29405 | CRITICAL | 9.8 | 1.7% | Jun 8, 2023 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici... |
| CVE-2023-29404 | CRITICAL | 9.8 | 1.8% | Jun 8, 2023 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici... |
| CVE-2023-29403 | HIGH | 7.8 | 0.4% | Jun 8, 2023 | On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can... |
| CVE-2023-29402 | CRITICAL | 9.8 | 1.7% | Jun 8, 2023 | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when ru... |
| CVE-2023-29401 | MEDIUM | 4.3 | 0.5% | Jun 8, 2023 | The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename ... |
| CVE-2023-24535 | HIGH | 7.5 | 1.1% | Jun 8, 2023 | Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minu... |
| CVE-2023-0954 | CRITICAL | 9.8 | 0.7% | Jun 8, 2023 | A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentia... |
| CVE-2023-34231 | HIGH | 8.8 | 2.0% | Jun 8, 2023 | gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snow... |
| CVE-2023-32749 | HIGH | 8.8 | 14.2% | Jun 8, 2023 | Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t... |
| CVE-2023-34962 | HIGH | 8.1 | 0.7% | Jun 8, 2023 | Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another stu... |
| CVE-2023-34961 | MEDIUM | 6.1 | 0.4% | Jun 8, 2023 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/co... |
| CVE-2023-34959 | MEDIUM | 5.3 | 0.6% | Jun 8, 2023 | An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain i... |
| CVE-2023-34958 | MEDIUM | 4.3 | 0.4% | Jun 8, 2023 | Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download docum... |
| CVE-2023-34096 | HIGH | 8.8 | 62.7% | Jun 8, 2023 | Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends.... |
| CVE-2023-3165 | MEDIUM | 6.1 | 0.6% | Jun 8, 2023 | A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. A... |
| CVE-2023-34571 | MEDIUM | 6.7 | 0.3% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /gofo... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now