2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28322 | LOW | 3.7 | 2.2% | May 26, 2023 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously u... |
| CVE-2023-28321 | MEDIUM | 5.9 | 1.8% | May 26, 2023 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patt... |
| CVE-2023-28320 | MEDIUM | 5.9 | 2.7% | May 26, 2023 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for reso... |
| CVE-2023-28319 | HIGH | 7.5 | 2.5% | May 26, 2023 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's publ... |
| CVE-2023-33255 | MEDIUM | 6.1 | 0.9% | May 26, 2023 | An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded in... |
| CVE-2023-33247 | HIGH | 7.5 | 0.5% | May 26, 2023 | Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthentic... |
| CVE-2023-33197 | MEDIUM | 5.4 | 0.7% | May 26, 2023 | Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the U... |
| CVE-2023-32681 | MEDIUM | 6.1 | 2.8% | May 26, 2023 | Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination s... |
| CVE-2023-32318 | MEDIUM | 6.7 | 0.2% | May 26, 2023 | Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextclo... |
| CVE-2023-2283 | MEDIUM | 6.5 | 1.1% | May 26, 2023 | A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_... |
| CVE-2023-22970 | HIGH | 7.8 | 0.5% | May 26, 2023 | Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. |
| CVE-2023-20868 | MEDIUM | 6.1 | 0.5% | May 26, 2023 | NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can i... |
| CVE-2023-1981 | MEDIUM | 5.5 | 0.4% | May 26, 2023 | A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the a... |
| CVE-2023-1667 | MEDIUM | 6.5 | 1.3% | May 26, 2023 | A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authent... |
| CVE-2023-1664 | MEDIUM | 6.5 | 0.4% | May 26, 2023 | A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be ena... |
| CVE-2023-33780 | MEDIUM | 5.4 | 0.5% | May 26, 2023 | A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execut... |
| CVE-2023-33779 | HIGH | 8.8 | 1.1% | May 26, 2023 | A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another use... |
| CVE-2023-31227 | HIGH | 7.5 | 0.4% | May 26, 2023 | The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may... |
| CVE-2023-31226 | HIGH | 7.5 | 0.4% | May 26, 2023 | The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vul... |
| CVE-2023-31225 | LOW | 3.3 | 0.1% | May 26, 2023 | The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download fail... |
| CVE-2023-2817 | MEDIUM | 5.4 | 0.4% | May 26, 2023 | A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including ... |
| CVE-2023-2002 | MEDIUM | 6.8 | 1.5% | May 26, 2023 | A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.... |
| CVE-2023-20883 | HIGH | 7.5 | 0.9% | May 26, 2023 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, th... |
| CVE-2023-20882 | MEDIUM | 5.9 | 0.6% | May 26, 2023 | In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a ... |
| CVE-2023-0117 | MEDIUM | 5.3 | 0.4% | May 26, 2023 | The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now