2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6679MEDIUM5.5A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Di...
CVE-2023-49795MEDIUM5.3MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side req...
CVE-2023-48715MEDIUM5.4Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.9...
CVE-2023-6538MEDIUM6.5SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe...
CVE-2023-50465MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by ...
CVE-2023-50463MEDIUM6.5The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows att...
CVE-2023-50457MEDIUM4.3An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge bas...
CVE-2023-50456MEDIUM5.3An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails ...
CVE-2023-50454MEDIUM5.9An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to exte...
CVE-2023-50453MEDIUM5.3An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This ...
CVE-2023-5870MEDIUM4.4A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logic...
CVE-2023-5868MEDIUM4.3A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by ex...
CVE-2023-6653MEDIUM4.3A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problemat...
CVE-2023-6650MEDIUM6.1A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issu...
CVE-2023-6649MEDIUM6.1A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problema...
CVE-2023-50431MEDIUM5.5sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an inform...
CVE-2023-6646MEDIUM5.4A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipu...
CVE-2023-50430MEDIUM6.4The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Pr...
CVE-2023-50428MEDIUM5.3In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obf...
CVE-2023-28874MEDIUM6.1The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary site...
CVE-2023-28873MEDIUM5.4An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown edito...
CVE-2023-28871MEDIUM4.3Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the oper...
CVE-2023-28870MEDIUM6.5Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to ...
CVE-2023-28869MEDIUM6.5Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on ...
CVE-2023-47465MEDIUM5.5An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read fun...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now