2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6679 | MEDIUM | 5.5 | 0.3% | Dec 11, 2023 | A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Di... |
| CVE-2023-49795 | MEDIUM | 5.3 | 0.4% | Dec 11, 2023 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side req... |
| CVE-2023-48715 | MEDIUM | 5.4 | 0.5% | Dec 11, 2023 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.9... |
| CVE-2023-6538 | MEDIUM | 6.5 | 1.6% | Dec 11, 2023 | SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe... |
| CVE-2023-50465 | MEDIUM | 5.4 | 0.6% | Dec 11, 2023 | A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by ... |
| CVE-2023-50463 | MEDIUM | 6.5 | 0.7% | Dec 10, 2023 | The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows att... |
| CVE-2023-50457 | MEDIUM | 4.3 | 0.4% | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge bas... |
| CVE-2023-50456 | MEDIUM | 5.3 | 0.4% | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails ... |
| CVE-2023-50454 | MEDIUM | 5.9 | 0.3% | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to exte... |
| CVE-2023-50453 | MEDIUM | 5.3 | 0.5% | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This ... |
| CVE-2023-5870 | MEDIUM | 4.4 | 2.6% | Dec 10, 2023 | A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logic... |
| CVE-2023-5868 | MEDIUM | 4.3 | 2.8% | Dec 10, 2023 | A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by ex... |
| CVE-2023-6653 | MEDIUM | 4.3 | 0.4% | Dec 10, 2023 | A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problemat... |
| CVE-2023-6650 | MEDIUM | 6.1 | 0.8% | Dec 10, 2023 | A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issu... |
| CVE-2023-6649 | MEDIUM | 6.1 | 0.8% | Dec 10, 2023 | A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problema... |
| CVE-2023-50431 | MEDIUM | 5.5 | 0.3% | Dec 9, 2023 | sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an inform... |
| CVE-2023-6646 | MEDIUM | 5.4 | 0.6% | Dec 9, 2023 | A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipu... |
| CVE-2023-50430 | MEDIUM | 6.4 | 0.4% | Dec 9, 2023 | The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Pr... |
| CVE-2023-50428 | MEDIUM | 5.3 | 0.8% | Dec 9, 2023 | In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obf... |
| CVE-2023-28874 | MEDIUM | 6.1 | 0.5% | Dec 9, 2023 | The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary site... |
| CVE-2023-28873 | MEDIUM | 5.4 | 0.4% | Dec 9, 2023 | An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown edito... |
| CVE-2023-28871 | MEDIUM | 4.3 | 0.6% | Dec 9, 2023 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the oper... |
| CVE-2023-28870 | MEDIUM | 6.5 | 0.7% | Dec 9, 2023 | Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to ... |
| CVE-2023-28869 | MEDIUM | 6.5 | 0.8% | Dec 9, 2023 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on ... |
| CVE-2023-47465 | MEDIUM | 5.5 | 0.2% | Dec 9, 2023 | An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read fun... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now