CVEs from 2023

6,107 normalized CVEs published or assigned in this year.

Total
6,107
critical
critical 240
high
high 1,530
medium
medium 1,393
low
low 32
% Critical
3.9%
% with KEV
2.7%
% with exploit
3.5%

Top vendors

Top products

  • office 29
  • office_long_term_servicing_channel 15
  • 365_apps 14
  • ftmg-esr50sxx 8
  • ftmg-esn40sxx 8
  • ftmg-esd25axx 8
  • ftmg-esr40sxx 8
  • ftmg-esd15axx 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-4091 medium 5.5 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-26965 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-3576 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-1981 medium 5.5 3y ago Moderate: avahi security update
CVE-2023-3978 medium 5.5 3y ago Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVE-2023-24998 medium 5.5 3y ago Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploa…
CVE-2023-28708 medium 5.5 3y ago When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to …
CVE-2023-28370 medium 5.5 3y ago Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acc…
CVE-2023-39319 medium 5.5 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39322 medium 5.5 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39318 medium 5.5 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39321 medium 5.5 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-38710 medium 5.5 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-27533 medium 5.5 3y ago A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during serve…
CVE-2023-53088 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix UaF in listener shutdown As reported by Christoph after having refactored the passive socket initialization, the mptcp…
CVE-2023-53103 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: bonding: restore bond's IFF_SLAVE flag if a non-eth dev enslave fails syzbot reported a warning[1] where the bond device itself i…
CVE-2023-54320 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: pmc: Fix memory leak in amd_pmc_stb_debugfs_open_v2() Function amd_pmc_stb_debugfs_open_v2() may be called when…
CVE-2023-28625 medium 5.5 3y ago RHSA-2023:6940: mod_auth_openidc:2.3 security and bug fix update (Moderate)
CVE-2023-44271 medium 5.5 3y ago RHSA-2024:3005: python-pillow security update (Moderate)
CVE-2023-0567 medium 5.5 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2023-3823 medium 5.5 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2023-3824 medium 5.5 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2023-0568 medium 5.5 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2023-3247 medium 5.5 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2023-22067 medium 5.5 3y ago RHSA-2024:0866: java-1.8.0-ibm security update (Moderate)
CVE-2023-22025 medium 5.5 3y ago RHSA-2023:6887: java-21-openjdk security and bug fix update (Moderate)
CVE-2023-29409 medium 5.5 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39323 medium 5.5 3y ago RHBA-2023:6928: go-toolset:rhel8 bug fix and enhancement update (Moderate)
CVE-2023-36799 medium 5.5 3y ago RHSA-2023:6247: .NET 7.0 security update (Moderate)
CVE-2023-2602 medium 5.5 3y ago RHSA-2023:4524: libcap security update (Moderate)
CVE-2023-30630 medium 5.5 3y ago RHSA-2023:5252: dmidecode security update (Moderate)
CVE-2023-20593 medium 5.5 3y ago Moderate: linux-firmware security update
CVE-2023-38200 medium 5.5 3y ago Moderate: keylime security update
CVE-2023-38201 medium 5.5 3y ago Moderate: keylime security update
CVE-2023-38633 medium 5.5 3y ago Moderate: librsvg2 security update
CVE-2023-2603 medium 5.5 3y ago RHSA-2023:4524: libcap security update (Moderate)
CVE-2023-29303 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker c…
CVE-2023-38245 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulner…
CVE-2023-38238 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker c…
CVE-2023-38236 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-38235 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-34969 medium 5.5 3y ago D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor …
CVE-2023-28484 medium 5.5 3y ago In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
CVE-2023-30079 medium 5.5 3y ago Moderate: libeconf security update
CVE-2023-29469 medium 5.5 3y ago An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various l…
CVE-2023-28322 medium 5.5 3y ago An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even whe…
CVE-2023-28321 medium 5.5 3y ago An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl…
CVE-2023-22652 medium 5.5 3y ago Moderate: libeconf security update
CVE-2023-32681 medium 5.5 3y ago Moderate: python-requests security update
CVE-2023-3347 medium 5.5 3y ago RHSA-2023:4328: samba security and bug fix update (Moderate)
CVE-2023-30581 medium 5.5 3y ago Moderate: nodejs:18 security, bug fix, and enhancement update
CVE-2023-30588 medium 5.5 3y ago Moderate: nodejs:18 security, bug fix, and enhancement update
CVE-2023-30589 medium 5.5 3y ago Moderate: nodejs:18 security, bug fix, and enhancement update
CVE-2023-30590 medium 5.5 3y ago Moderate: nodejs:18 security, bug fix, and enhancement update
CVE-2023-22044 medium 5.5 3y ago RHSA-2023:4159: java-17-openjdk security and bug fix update (Moderate)
CVE-2023-25193 medium 5.5 3y ago RHSA-2024:2980: harfbuzz security update (Moderate)
CVE-2023-3128 medium 5.5 3y ago RHSA-2023:6972: grafana security and enhancement update (Moderate)
CVE-2023-33162 medium 5.5 5.5 3y ago Microsoft Excel Information Disclosure Vulnerability
CVE-2023-36617 medium 5.5 3y ago RHSA-2024:4499: ruby security update (Moderate)
CVE-2023-26604 medium 5.5 3y ago systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifical…
CVE-2023-0803 medium 5.5 3y ago RHSA-2023:5353: libtiff security update (Moderate)
CVE-2023-0800 medium 5.5 3y ago RHSA-2023:5353: libtiff security update (Moderate)
CVE-2023-0802 medium 5.5 3y ago RHSA-2023:5353: libtiff security update (Moderate)
CVE-2023-28466 medium 5.5 3y ago do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
CVE-2023-0801 medium 5.5 3y ago RHSA-2023:5353: libtiff security update (Moderate)
CVE-2023-0797 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-0796 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-0464 medium 5.5 3y ago Moderate: openssl security and bug fix update
CVE-2023-0804 medium 5.5 3y ago RHSA-2023:5353: libtiff security update (Moderate)
CVE-2023-0795 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-0799 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-2650 medium 5.5 3y ago Moderate: openssl security and bug fix update
CVE-2023-2700 medium 5.5 3y ago RHSA-2023:3822: virt:rhel and virt-devel:rhel security and bug fix update (Moderate)
CVE-2023-1255 medium 5.5 3y ago Moderate: openssl security and bug fix update
CVE-2023-0466 medium 5.5 3y ago Moderate: openssl security and bug fix update
CVE-2023-2454 medium 5.5 3y ago Moderate: postgresql:15 security update
CVE-2023-2455 medium 5.5 3y ago Moderate: postgresql:15 security update
CVE-2023-0798 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-0465 medium 5.5 3y ago Moderate: openssl security and bug fix update
CVE-2023-24539 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-29400 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24538 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24540 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24537 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24536 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24534 medium 5.5 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-25565 medium 5.5 3y ago RHSA-2023:3097: gssntlmssp security update (Moderate)
CVE-2023-25563 medium 5.5 3y ago RHSA-2023:3097: gssntlmssp security update (Moderate)
CVE-2023-25564 medium 5.5 3y ago RHSA-2023:3097: gssntlmssp security update (Moderate)
CVE-2023-25566 medium 5.5 3y ago RHSA-2023:3097: gssntlmssp security update (Moderate)
CVE-2023-25567 medium 5.5 3y ago RHSA-2023:3097: gssntlmssp security update (Moderate)
CVE-2023-30774 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-1017 medium 5.5 3y ago Moderate: libtpms security update
CVE-2023-30775 medium 5.5 3y ago Moderate: libtiff security update
CVE-2023-0664 medium 5.5 3y ago A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their p…
CVE-2023-1018 medium 5.5 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2023-23936 medium 5.5 3y ago RHSA-2023:1583: nodejs:18 security, bug fix, and enhancement update (Moderate)
CVE-2023-24807 medium 5.5 3y ago RHSA-2023:1583: nodejs:18 security, bug fix, and enhancement update (Moderate)
CVE-2023-23009 medium 5.5 3y ago RHSA-2023:3095: libreswan security and bug fix update (Moderate)
CVE-2023-27535 medium 5.5 3y ago An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created con…