2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0847HIGH8.1 The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write ...
CVE-2023-25575MEDIUM6.5API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with...
CVE-2023-1095MEDIUM5.5In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction o...
CVE-2023-22999MEDIUM5.5In the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev retur...
CVE-2023-22998MEDIUM5.5In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table r...
CVE-2023-22997MEDIUM5.5In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expect...
CVE-2023-22996MEDIUM5.5In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference aft...
CVE-2023-1100CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This aff...
CVE-2023-1099CRITICAL9.8A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affecte...
CVE-2023-27372CRITICAL9.8SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T...
CVE-2023-27371MEDIUM5.9GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data b...
CVE-2023-1065MEDIUM5.3This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, whi...
CVE-2023-1017HIGH7.8An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of...
CVE-2023-27320HIGH7.2Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
CVE-2023-25432HIGH7.2An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue inst...
CVE-2023-25431MEDIUM4.8An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/as...
CVE-2023-1018MEDIUM5.5An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 co...
CVE-2023-27295MEDIUM5.4Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can e...
CVE-2023-27294MEDIUM5.4Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted...
CVE-2023-27293MEDIUM6.1Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javas...
CVE-2023-27292MEDIUM5.4An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa...
CVE-2023-25540HIGH7.1 Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could pot...
CVE-2023-23689HIGH7.5 Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains...
CVE-2023-20948HIGH7.5In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. Thi...
CVE-2023-20946CRITICAL9.8In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now