2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32676HIGH7.2Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo...
CVE-2023-32321CRITICAL9.8CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee...
CVE-2023-32319MEDIUM6.5Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints...
CVE-2023-32317HIGH7.2Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo...
CVE-2023-32316MEDIUM4.3CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organiz...
CVE-2023-32315HIGH7.5Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based...
CVE-2023-32311MEDIUM4.3CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organ...
CVE-2023-32307HIGH7.5Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-85...
CVE-2023-31128HIGH8.8NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `...
CVE-2023-2898MEDIUM4.7There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw all...
CVE-2023-27311MEDIUM5.3NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architectu...
CVE-2023-21516CRITICAL9.6XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API ...
CVE-2023-21515HIGH8.8InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 al...
CVE-2023-21514HIGH8.8Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execu...
CVE-2023-33196MEDIUM5.4Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. T...
CVE-2023-33194MEDIUM4.8Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output i...
CVE-2023-33187MEDIUM6.5Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when...
CVE-2023-33185MEDIUM5.4Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS S...
CVE-2023-2879HIGH7.5GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or cra...
CVE-2023-2858MEDIUM6.5NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture...
CVE-2023-2857MEDIUM6.5BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2856MEDIUM6.5VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted ca...
CVE-2023-2855MEDIUM6.5Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fi...
CVE-2023-2854MEDIUM6.5BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2825HIGH7.5An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now