2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6915MEDIUM5.5A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attac...
CVE-2023-50290MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes ...
CVE-2023-46749MEDIUM6.5Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentica...
CVE-2023-51071MEDIUM6.5An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers ...
CVE-2023-51068MEDIUM5.4An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build...
CVE-2023-51067MEDIUM6.1An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Bui...
CVE-2023-51064MEDIUM6.1QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerab...
CVE-2023-51062MEDIUM5.3An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0...
CVE-2023-51805MEDIUM6.5SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information ...
CVE-2023-50072MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension ...
CVE-2023-49099MEDIUM4.3Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with ...
CVE-2023-6683MEDIUM6.5A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f...
CVE-2023-31032MEDIUM5.5NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A s...
CVE-2023-28899MEDIUM5.5By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdow...
CVE-2023-51978MEDIUM6.5In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerab...
CVE-2023-28898MEDIUM5.3The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when...
CVE-2023-49260MEDIUM6.1An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It c...
CVE-2023-49258MEDIUM6.1User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS v...
CVE-2023-6955MEDIUM5.3A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, ...
CVE-2023-4812MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting...
CVE-2023-2030MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and...
CVE-2023-51806MEDIUM5.4File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
CVE-2023-51790MEDIUM6.1Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the l...
CVE-2023-50920MEDIUM5.5An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot,...
CVE-2023-40362MEDIUM4.3An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protectio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now