2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2878 | MEDIUM | 5.5 | 0.4% | Jun 7, 2023 | Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs. |
| CVE-2023-20889 | HIGH | 7.5 | 79.1% | Jun 7, 2023 | Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to ... |
| CVE-2023-20888 | HIGH | 8.8 | 82.3% | Jun 7, 2023 | Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network acc... |
| CVE-2023-20887 | CRITICAL | 9.8 | 98.1% | Jun 7, 2023 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware... |
| CVE-2023-33498 | HIGH | 8.8 | 0.7% | Jun 7, 2023 | alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file. |
| CVE-2023-3140 | MEDIUM | 4.3 | 0.4% | Jun 7, 2023 | Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulne... |
| CVE-2023-30576 | HIGH | 8.1 | 1.1% | Jun 7, 2023 | Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, thi... |
| CVE-2023-30575 | HIGH | 7.5 | 1.2% | Jun 7, 2023 | Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole... |
| CVE-2023-2541 | MEDIUM | 5.3 | 0.6% | Jun 7, 2023 | The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about ... |
| CVE-2023-1388 | HIGH | 8.1 | 0.6% | Jun 7, 2023 | A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the mac... |
| CVE-2023-0976 | HIGH | 7.8 | 0.6% | Jun 7, 2023 | A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file... |
| CVE-2023-2187 | MEDIUM | 5.3 | 0.6% | Jun 7, 2023 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to... |
| CVE-2023-2186 | CRITICAL | 9.8 | 0.7% | Jun 7, 2023 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted... |
| CVE-2023-33538 | HIGH | 8.8 | 42.6% | Jun 7, 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili... |
| CVE-2023-33537 | HIGH | 8.1 | 0.9% | Jun 7, 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo... |
| CVE-2023-33536 | HIGH | 8.1 | 0.9% | Jun 7, 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo... |
| CVE-2023-0668 | MEDIUM | 6.5 | 2.3% | Jun 7, 2023 | Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and... |
| CVE-2023-0667 | MEDIUM | 6.5 | 2.0% | Jun 7, 2023 | Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior,... |
| CVE-2023-0666 | MEDIUM | 6.5 | 2.3% | Jun 7, 2023 | Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, ... |
| CVE-2023-3126 | MEDIUM | 4.3 | 0.7% | Jun 7, 2023 | The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2023-3125 | MEDIUM | 6.5 | 0.7% | Jun 7, 2023 | The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2023-3124 | HIGH | 8.8 | 22.7% | Jun 7, 2023 | The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check... |
| CVE-2023-33604 | CRITICAL | 9.1 | 0.8% | Jun 7, 2023 | Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp... |
| CVE-2023-33601 | HIGH | 8.8 | 0.9% | Jun 7, 2023 | An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary co... |
| CVE-2023-33782 | HIGH | 8.8 | 42.9% | Jun 7, 2023 | D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now