2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32676 | HIGH | 7.2 | 0.9% | May 26, 2023 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo... |
| CVE-2023-32321 | CRITICAL | 9.8 | 1.7% | May 26, 2023 | CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee... |
| CVE-2023-32319 | MEDIUM | 6.5 | 0.7% | May 26, 2023 | Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints... |
| CVE-2023-32317 | HIGH | 7.2 | 0.9% | May 26, 2023 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo... |
| CVE-2023-32316 | MEDIUM | 4.3 | 0.4% | May 26, 2023 | CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organiz... |
| CVE-2023-32315 | HIGH | 7.5 | 100.0% | May 26, 2023 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based... |
| CVE-2023-32311 | MEDIUM | 4.3 | 0.4% | May 26, 2023 | CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organ... |
| CVE-2023-32307 | HIGH | 7.5 | 1.1% | May 26, 2023 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-85... |
| CVE-2023-31128 | HIGH | 8.8 | 3.3% | May 26, 2023 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `... |
| CVE-2023-2898 | MEDIUM | 4.7 | 0.2% | May 26, 2023 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw all... |
| CVE-2023-27311 | MEDIUM | 5.3 | 0.6% | May 26, 2023 | NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architectu... |
| CVE-2023-21516 | CRITICAL | 9.6 | 0.5% | May 26, 2023 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API ... |
| CVE-2023-21515 | HIGH | 8.8 | 0.5% | May 26, 2023 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 al... |
| CVE-2023-21514 | HIGH | 8.8 | 0.5% | May 26, 2023 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execu... |
| CVE-2023-33196 | MEDIUM | 5.4 | 0.7% | May 26, 2023 | Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. T... |
| CVE-2023-33194 | MEDIUM | 4.8 | 0.6% | May 26, 2023 | Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output i... |
| CVE-2023-33187 | MEDIUM | 6.5 | 0.3% | May 26, 2023 | Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when... |
| CVE-2023-33185 | MEDIUM | 5.4 | 0.2% | May 26, 2023 | Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS S... |
| CVE-2023-2879 | HIGH | 7.5 | 1.6% | May 26, 2023 | GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or cra... |
| CVE-2023-2858 | MEDIUM | 6.5 | 1.8% | May 26, 2023 | NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture... |
| CVE-2023-2857 | MEDIUM | 6.5 | 0.9% | May 26, 2023 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file |
| CVE-2023-2856 | MEDIUM | 6.5 | 1.8% | May 26, 2023 | VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted ca... |
| CVE-2023-2855 | MEDIUM | 6.5 | 1.7% | May 26, 2023 | Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fi... |
| CVE-2023-2854 | MEDIUM | 6.5 | 0.9% | May 26, 2023 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file |
| CVE-2023-2825 | HIGH | 7.5 | 71.6% | May 26, 2023 | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now