2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29277 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le... |
| CVE-2023-29276 | HIGH | 7.8 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could r... |
| CVE-2023-29275 | HIGH | 7.8 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ... |
| CVE-2023-29274 | HIGH | 7.8 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ... |
| CVE-2023-29273 | HIGH | 7.8 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing ... |
| CVE-2023-28361 | MEDIUM | 6.5 | 0.3% | May 11, 2023 | A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to acc... |
| CVE-2023-28360 | MEDIUM | 4.3 | 0.8% | May 11, 2023 | An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user... |
| CVE-2023-28359 | MEDIUM | 5.3 | 0.6% | May 11, 2023 | A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be e... |
| CVE-2023-28358 | MEDIUM | 6.1 | 0.4% | May 11, 2023 | A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allow... |
| CVE-2023-28357 | MEDIUM | 4.3 | 0.4% | May 11, 2023 | A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking... |
| CVE-2023-28356 | HIGH | 7.5 | 0.7% | May 11, 2023 | A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can ca... |
| CVE-2023-28325 | MEDIUM | 6.5 | 0.4% | May 11, 2023 | An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param... |
| CVE-2023-32058 | HIGH | 7.5 | 0.9% | May 11, 2023 | Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing ove... |
| CVE-2023-31497 | HIGH | 7.8 | 0.5% | May 11, 2023 | Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 a... |
| CVE-2023-31146 | CRITICAL | 9.1 | 1.2% | May 11, 2023 | Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, th... |
| CVE-2023-2664 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflo... |
| CVE-2023-2663 | MEDIUM | 5.5 | 0.5% | May 11, 2023 | In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. ... |
| CVE-2023-2662 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero. |
| CVE-2023-29791 | MEDIUM | 6.1 | 0.4% | May 11, 2023 | kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. |
| CVE-2023-32082 | MEDIUM | 4.3 | 0.7% | May 11, 2023 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the Leas... |
| CVE-2023-29195 | MEDIUM | 4.3 | 1.0% | May 11, 2023 | Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16... |
| CVE-2023-27870 | MEDIUM | 5.9 | 0.7% | May 11, 2023 | IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a downl... |
| CVE-2023-27554 | MEDIUM | 6.3 | 0.9% | May 11, 2023 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces... |
| CVE-2023-30394 | MEDIUM | 6.1 | 0.6% | May 11, 2023 | The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this is... |
| CVE-2023-2444 | HIGH | 8.8 | 0.4% | May 11, 2023 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now