2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40539Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-40223Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-40159Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-50304HIGH8.2IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE)...
CVE-2023-6708MEDIUM5.4The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers...
CVE-2023-43971MEDIUM6.1Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode ...
CVE-2023-42010LOW3.7IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitiv...
CVE-2023-4976CRITICAL9.3A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an un...
CVE-2023-7272HIGH7.5In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to caus...
CVE-2023-52291MEDIUM4.7In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str...
CVE-2023-7013MEDIUM4.7Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potent...
CVE-2023-7012CRITICAL9.6Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convi...
CVE-2023-7011MEDIUM6.5Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to...
CVE-2023-7010HIGH8.8Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap c...
CVE-2023-4860CRITICAL9.6Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromis...
CVE-2023-31456MEDIUM5.4There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be ...
CVE-2023-52886MEDIUM6.4In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descri...
CVE-2023-52290HIGH8.1In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from...
CVE-2023-49566HIGH8.8 In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2...
CVE-2023-46801HIGH8.8 In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution v...
CVE-2023-41916MEDIUM6.5 In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql ...
CVE-2023-52885HIGH7.8In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() Aft...
CVE-2023-39329MEDIUM6.5A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a cra...
CVE-2023-39327MEDIUM4.3A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuou...
CVE-2023-41093LOW3.1Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now