CVEs from 2023

6,120 normalized CVEs published or assigned in this year.

Total
6,120
critical
critical 239
high
high 1,529
medium
medium 1,388
low
low 32
% Critical
3.9%
% with KEV
2.7%
% with exploit
3.5%

Top vendors

Top products

  • office 29
  • office_long_term_servicing_channel 15
  • 365_apps 14
  • ftmg-esr50sxx 8
  • ftmg-esn40sxx 8
  • ftmg-esd25axx 8
  • ftmg-esr40sxx 8
  • ftmg-esd15axx 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-22097 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21919 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21945 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21933 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22033 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21976 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21946 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22070 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22079 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-45285 medium 5.5 2y ago Moderate: golang security update
CVE-2023-22110 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-45539 medium 5.5 2y ago RHSA-2024:8849: haproxy security update (Moderate)
CVE-2023-21982 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22046 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22112 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22005 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22032 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22048 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22104 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22057 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22058 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22059 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21911 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-40225 medium 5.5 2y ago Moderate: haproxy security update
CVE-2023-21953 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22056 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22038 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21935 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22115 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22054 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22114 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21980 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22007 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-22103 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-21947 medium 5.5 2y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-5992 medium 5.5 2y ago RHSA-2024:0967: opensc security update (Moderate)
CVE-2023-5676 medium 5.5 2y ago RHSA-2024:0866: java-1.8.0-ibm security update (Moderate)
CVE-2023-42465 medium 5.5 2y ago Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling …
CVE-2023-28486 medium 5.5 2y ago Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-28487 medium 5.5 2y ago Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2023-6135 medium 5.5 2y ago Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox <…
CVE-2023-5981 medium 5.5 2y ago RHSA-2024:0627: gnutls security update (Moderate)
CVE-2023-45648 medium 5.5 2y ago Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not c…
CVE-2023-45803 medium 5.5 2y ago Moderate: fence-agents security and bug fix update
CVE-2023-42794 medium 5.5 2y ago Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in pro…
CVE-2023-47234 medium 5.5 2y ago An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory …
CVE-2023-47235 medium 5.5 2y ago An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdra…
CVE-2023-7104 medium 5.5 2y ago RHSA-2024:0253: sqlite security update (Moderate)
CVE-2023-41080 medium 5.5 2y ago URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 thro…
CVE-2023-38407 medium 5.5 2y ago bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
CVE-2023-38409 medium 5.5 2y ago An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_…
CVE-2023-38406 medium 5.5 2y ago bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
CVE-2023-42795 medium 5.5 2y ago Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0…
CVE-2023-4001 medium 5.5 2y ago Moderate: grub2 security update
CVE-2023-5455 medium 5.5 2y ago RHSA-2024:0143: idm:DL1 security update (Moderate)
CVE-2023-5388 medium 5.5 2y ago Moderate: nss security update
CVE-2023-6377 medium 5.5 3y ago A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege …
CVE-2023-6478 medium 5.5 3y ago A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive informat…
CVE-2023-5367 medium 5.5 3y ago A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty fu…
CVE-2023-40660 medium 5.5 3y ago RHSA-2023:7876: opensc security update (Moderate)
CVE-2023-4535 medium 5.5 3y ago Moderate: opensc security update
CVE-2023-40661 medium 5.5 3y ago RHSA-2023:7876: opensc security update (Moderate)
CVE-2023-51384 medium 5.5 5.5 3y ago In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these const…
CVE-2023-36009 medium 5.5 5.5 3y ago Microsoft Word Information Disclosure Vulnerability
CVE-2023-43804 medium 5.5 3y ago Moderate: python3.11-urllib3 security update
CVE-2023-39615 medium 5.5 3y ago RHSA-2024:0119: libxml2 security update (Moderate)
CVE-2023-53657 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ice: Don't tx before switchdev is fully configured There is possibility that ice_eswitch_port_start_xmit might be called while so…
CVE-2023-53996 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: x86/sev: Make enc_dec_hypercall() accept a size instead of npages enc_dec_hypercall() accepted a page count instead of a size, wh…
CVE-2023-54170 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: keys: Fix linking a duplicate key to a keyring's assoc_array When making a DNS query inside the kernel using dns_query(), the req…
CVE-2023-6460 medium 5.5 5.5 3y ago Logging of the firestore key within nodejs-firestore
CVE-2023-20240 medium 5.5 5.5 3y ago Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an a…
CVE-2023-44357 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-44348 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-44360 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-44361 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker c…
CVE-2023-44358 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-44339 medium 5.5 5.5 3y ago Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac…
CVE-2023-36049 medium 5.5 3y ago RHSA-2023:7258: dotnet6.0 security update (Moderate)
CVE-2023-36558 medium 5.5 3y ago RHSA-2023:7258: dotnet6.0 security update (Moderate)
CVE-2023-4042 medium 5.5 3y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2023-3301 medium 5.5 3y ago A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could…
CVE-2023-53576 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: null_blk: Always check queue mode setting from configfs Make sure to check device queue mode in the null_validate_conf() and retu…
CVE-2023-28625 medium 5.5 3y ago RHSA-2023:6940: mod_auth_openidc:2.3 security and bug fix update (Moderate)
CVE-2023-28370 medium 5.5 3y ago Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acc…
CVE-2023-41105 medium 5.5 3y ago RHSA-2023:7024: python3.11 security update (Moderate)
CVE-2023-53867 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimming caps When trimming the caps and just after the 'session->s_cap_lock' is rele…
CVE-2023-36054 medium 5.5 3y ago Moderate: krb5 security and bug fix update
CVE-2023-37369 medium 5.5 3y ago In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefi…
CVE-2023-27522 medium 5.5 3y ago HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header c…
CVE-2023-34241 medium 5.5 3y ago RHSA-2023:7165: cups security and bug fix update (Moderate)
CVE-2023-54004 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). syzbot reported [0] a null-ptr-deref in sk_get_rmem0() while…
CVE-2023-24998 medium 5.5 3y ago Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploa…
CVE-2023-39976 medium 5.5 3y ago Moderate: libqb security update
CVE-2023-53392 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->fw_client is set to NULL. If a bus driver is reg…
CVE-2023-3750 medium 5.5 3y ago Moderate: libvirt security, bug fix, and enhancement update
CVE-2023-34966 medium 5.5 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-42669 medium 5.5 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-53205 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change…
CVE-2023-39321 medium 5.5 3y ago RHSA-2024:2988: container-tools:rhel8 security update (Moderate)
CVE-2023-3316 medium 5.5 3y ago Moderate: libtiff security update