2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29277MEDIUM5.5Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le...
CVE-2023-29276HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could r...
CVE-2023-29275HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-29274HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-29273HIGH7.8Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ...
CVE-2023-28361MEDIUM6.5A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to acc...
CVE-2023-28360MEDIUM4.3An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user...
CVE-2023-28359MEDIUM5.3A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be e...
CVE-2023-28358MEDIUM6.1A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allow...
CVE-2023-28357MEDIUM4.3A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking...
CVE-2023-28356HIGH7.5A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can ca...
CVE-2023-28325MEDIUM6.5An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param...
CVE-2023-32058HIGH7.5Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing ove...
CVE-2023-31497HIGH7.8Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 a...
CVE-2023-31146CRITICAL9.1Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, th...
CVE-2023-2664MEDIUM5.5 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflo...
CVE-2023-2663MEDIUM5.5 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. ...
CVE-2023-2662MEDIUM5.5In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
CVE-2023-29791MEDIUM6.1kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
CVE-2023-32082MEDIUM4.3etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the Leas...
CVE-2023-29195MEDIUM4.3Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16...
CVE-2023-27870MEDIUM5.9 IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a downl...
CVE-2023-27554MEDIUM6.3 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces...
CVE-2023-30394MEDIUM6.1The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this is...
CVE-2023-2444HIGH8.8 A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now