2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-52706MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: sim: fix a memory leak Fix an inverted logic...
CVE-2023-52705MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position...
CVE-2023-52704MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: freezer,umh: Fix call_usermode_helper_exec() vs SIG...
CVE-2023-52703MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/usb: kalmia: Don't pass act_len in usb_bulk_msg...
CVE-2023-52702MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible memory leak in ovs_m...
CVE-2023-52701HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: use a bounce buffer for copying skb->mark syz...
CVE-2023-52700MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tipc: fix kernel warning when sending SYN message ...
CVE-2023-3943CRITICAL10Stack-based Buffer Overflow vulnerability in ZkTeco-based OEM devices allows, in some cases, the execution of arbitrary ...
CVE-2023-3942HIGH7.5An 'SQL Injection' vulnerability, due to improper neutralization of special elements used in SQL commands, exists in ZKT...
CVE-2023-3941CRITICAL10Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system w...
CVE-2023-3940HIGH7.5Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. ...
CVE-2023-3939CRITICAL10Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-base...
CVE-2023-3938MEDIUM4.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM ...
CVE-2023-37929MEDIUM6.5The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an...
CVE-2023-49335HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
CVE-2023-49334HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.
CVE-2023-49333HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.
CVE-2023-49332HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
CVE-2023-49331HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
CVE-2023-49330HIGH8.8Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.
CVE-2023-52699MEDIUM5.3In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held...
CVE-2023-52424HIGH7.4The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted ...
CVE-2023-5597MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x thr...
CVE-2023-52698MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass...
CVE-2023-52697HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->head...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now