2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28322LOW3.7An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously u...
CVE-2023-28321MEDIUM5.9An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patt...
CVE-2023-28320MEDIUM5.9A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for reso...
CVE-2023-28319HIGH7.5A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's publ...
CVE-2023-33255MEDIUM6.1An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded in...
CVE-2023-33247HIGH7.5Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthentic...
CVE-2023-33197MEDIUM5.4Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the U...
CVE-2023-32681MEDIUM6.1Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination s...
CVE-2023-32318MEDIUM6.7Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextclo...
CVE-2023-2283MEDIUM6.5A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_...
CVE-2023-22970HIGH7.8Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
CVE-2023-20868MEDIUM6.1NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can i...
CVE-2023-1981MEDIUM5.5A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the a...
CVE-2023-1667MEDIUM6.5A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authent...
CVE-2023-1664MEDIUM6.5A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be ena...
CVE-2023-33780MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execut...
CVE-2023-33779HIGH8.8A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another use...
CVE-2023-31227HIGH7.5The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may...
CVE-2023-31226HIGH7.5The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vul...
CVE-2023-31225LOW3.3The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download fail...
CVE-2023-2817MEDIUM5.4A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including ...
CVE-2023-2002MEDIUM6.8A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock....
CVE-2023-20883HIGH7.5In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, th...
CVE-2023-20882MEDIUM5.9In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a ...
CVE-2023-0117MEDIUM5.3The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now