2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6915 | MEDIUM | 5.5 | 0.3% | Jan 15, 2024 | A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attac... |
| CVE-2023-50290 | MEDIUM | 6.5 | 68.7% | Jan 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes ... |
| CVE-2023-46749 | MEDIUM | 6.5 | 1.2% | Jan 15, 2024 | Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentica... |
| CVE-2023-51071 | MEDIUM | 6.5 | 0.5% | Jan 13, 2024 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers ... |
| CVE-2023-51068 | MEDIUM | 5.4 | 0.4% | Jan 13, 2024 | An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build... |
| CVE-2023-51067 | MEDIUM | 6.1 | 0.4% | Jan 13, 2024 | An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Bui... |
| CVE-2023-51064 | MEDIUM | 6.1 | 0.4% | Jan 13, 2024 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerab... |
| CVE-2023-51062 | MEDIUM | 5.3 | 0.5% | Jan 13, 2024 | An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0... |
| CVE-2023-51805 | MEDIUM | 6.5 | 0.6% | Jan 13, 2024 | SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information ... |
| CVE-2023-50072 | MEDIUM | 5.4 | 0.6% | Jan 13, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension ... |
| CVE-2023-49099 | MEDIUM | 4.3 | 0.3% | Jan 12, 2024 | Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with ... |
| CVE-2023-6683 | MEDIUM | 6.5 | 1.3% | Jan 12, 2024 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f... |
| CVE-2023-31032 | MEDIUM | 5.5 | 0.2% | Jan 12, 2024 | NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A s... |
| CVE-2023-28899 | MEDIUM | 5.5 | 0.1% | Jan 12, 2024 | By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdow... |
| CVE-2023-51978 | MEDIUM | 6.5 | 0.5% | Jan 12, 2024 | In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerab... |
| CVE-2023-28898 | MEDIUM | 5.3 | 0.2% | Jan 12, 2024 | The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when... |
| CVE-2023-49260 | MEDIUM | 6.1 | 0.3% | Jan 12, 2024 | An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It c... |
| CVE-2023-49258 | MEDIUM | 6.1 | 0.3% | Jan 12, 2024 | User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS v... |
| CVE-2023-6955 | MEDIUM | 5.3 | 0.6% | Jan 12, 2024 | A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, ... |
| CVE-2023-4812 | MEDIUM | 5.3 | 0.5% | Jan 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting... |
| CVE-2023-2030 | MEDIUM | 5.3 | 0.4% | Jan 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and... |
| CVE-2023-51806 | MEDIUM | 5.4 | 0.5% | Jan 12, 2024 | File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file. |
| CVE-2023-51790 | MEDIUM | 6.1 | 0.5% | Jan 12, 2024 | Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the l... |
| CVE-2023-50920 | MEDIUM | 5.5 | 0.2% | Jan 12, 2024 | An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot,... |
| CVE-2023-40362 | MEDIUM | 4.3 | 0.7% | Jan 12, 2024 | An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protectio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now