2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2878MEDIUM5.5Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
CVE-2023-20889HIGH7.5Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to ...
CVE-2023-20888HIGH8.8Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network acc...
CVE-2023-20887CRITICAL9.8Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware...
CVE-2023-33498HIGH8.8alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
CVE-2023-3140MEDIUM4.3Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulne...
CVE-2023-30576HIGH8.1Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, thi...
CVE-2023-30575HIGH7.5Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole...
CVE-2023-2541MEDIUM5.3The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about ...
CVE-2023-1388HIGH8.1 A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the mac...
CVE-2023-0976HIGH7.8 A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file...
CVE-2023-2187MEDIUM5.3On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to...
CVE-2023-2186CRITICAL9.8On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted...
CVE-2023-33538HIGH8.8TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili...
CVE-2023-33537HIGH8.1TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo...
CVE-2023-33536HIGH8.1TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo...
CVE-2023-0668MEDIUM6.5Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and...
CVE-2023-0667MEDIUM6.5Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior,...
CVE-2023-0666MEDIUM6.5Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, ...
CVE-2023-3126MEDIUM4.3The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2023-3125MEDIUM6.5The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2023-3124HIGH8.8The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check...
CVE-2023-33604CRITICAL9.1Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp...
CVE-2023-33601HIGH8.8An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary co...
CVE-2023-33782HIGH8.8D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now