2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0059MEDIUM5.4The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2023-24575HIGH7.8 Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privileg...
CVE-2023-26266HIGH7.3In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing target...
CVE-2023-26265MEDIUM5.3The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL...
CVE-2023-26253HIGH7.5In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.
CVE-2023-26249HIGH7.5Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially c...
CVE-2023-26242HIGH7.8afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflo...
CVE-2023-26235MEDIUM6.1JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.
CVE-2023-26234CRITICAL9.8JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
CVE-2023-23453CRITICAL9.8Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged...
CVE-2023-23452CRITICAL9.8Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged...
CVE-2023-25805CRITICAL9.8versionn, software for changing version information across multiple files, has a command injection vulnerability in all ...
CVE-2023-25656HIGH7.5notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to...
CVE-2023-25613CRITICAL9.8An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 
CVE-2023-25570HIGH7.5Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose...
CVE-2023-25569MEDIUM5.7Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page...
CVE-2023-24998HIGH7.5Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibi...
CVE-2023-26093CRITICAL9.8Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
CVE-2023-26092CRITICAL9.8Liima before 1.17.28 allows server-side template injection.
CVE-2023-26081HIGH7.5In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because aut...
CVE-2023-0919LOW3.5Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.
CVE-2023-0918CRITICAL9.8A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerabi...
CVE-2023-0917CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management S...
CVE-2023-0916HIGH8.8A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this v...
CVE-2023-0915HIGH8.8A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now