2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28331MEDIUM6.1Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVE-2023-28330MEDIUM6.5Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only...
CVE-2023-28329HIGH8.8Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only avail...
CVE-2023-24788HIGH8.8NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s...
CVE-2023-20861MEDIUM6.5In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versio...
CVE-2023-20859MEDIUM5.5In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is v...
CVE-2023-1613MEDIUM6.1A vulnerability has been found in Rebuild up to 3.2.3 and classified as problematic. This vulnerability affects unknown ...
CVE-2023-1612CRITICAL9.8A vulnerability, which was classified as critical, was found in Rebuild up to 3.2.3. This affects an unknown part of the...
CVE-2023-1513LOW3.3A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized ...
CVE-2023-1402MEDIUM4.3The course participation report required additional checks to prevent roles being displayed which the user did not have ...
CVE-2023-1252HIGH7.8A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations si...
CVE-2023-1249MEDIUM5.5A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the sy...
CVE-2023-0590MEDIUM4.7A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This fl...
CVE-2023-0056MEDIUM6.5An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue c...
CVE-2023-28436HIGH8Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the imple...
CVE-2023-26361MEDIUM4.9Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limit...
CVE-2023-26360HIGH8.6Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Acces...
CVE-2023-26359CRITICAL9.8Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization...
CVE-2023-25655CRITICAL9.8baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of ba...
CVE-2023-25654CRITICAL9.8baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in...
CVE-2023-1610CRITICAL9.8A vulnerability, which was classified as critical, has been found in Rebuild up to 3.2.3. Affected by this issue is some...
CVE-2023-1609MEDIUM5.4A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the...
CVE-2023-1608CRITICAL9.8A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability aff...
CVE-2023-1607HIGH8.8A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the f...
CVE-2023-1544MEDIUM6.3A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now