2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47799 | HIGH | 7.5 | 0.4% | Aug 25, 2025 | Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used... |
| CVE-2023-3867 | HIGH | 7.1 | 3.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup k... |
| CVE-2023-3865 | HIGH | 7.1 | 0.4% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_s... |
| CVE-2023-43692 | HIGH | 7.5 | 0.4% | Aug 14, 2025 | An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of... |
| CVE-2023-45584 | HIGH | 7.2 | 0.5% | Aug 12, 2025 | A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.... |
| CVE-2023-41532 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i... |
| CVE-2023-41531 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user... |
| CVE-2023-41524 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet... |
| CVE-2023-41523 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par... |
| CVE-2023-41522 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden... |
| CVE-2023-41521 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio... |
| CVE-2023-41520 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA... |
| CVE-2023-32256 | HIGH | 7.5 | 0.5% | Aug 1, 2025 | A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in mult... |
| CVE-2023-53157 | HIGH | 7.5 | 0.5% | Jul 28, 2025 | The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UD... |
| CVE-2023-53155 | HIGH | 7.2 | 0.5% | Jul 25, 2025 | goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter. |
| CVE-2023-7306 | HIGH | 7.5 | 0.3% | Jul 25, 2025 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi... |
| CVE-2023-47356 | HIGH | 8.8 | 0.7% | Jul 17, 2025 | Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th... |
| CVE-2023-41566 | HIGH | 8.1 | 0.3% | Jul 17, 2025 | OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend... |
| CVE-2023-52236 | HIGH | 7 | 0.2% | Jul 8, 2025 | A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All... |
| CVE-2023-51232 | HIGH | 7.5 | 0.9% | Jul 7, 2025 | Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive i... |
| CVE-2023-28910 | HIGH | 8 | 0.3% | Jun 28, 2025 | A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled a... |
| CVE-2023-28909 | HIGH | 8 | 0.5% | Jun 28, 2025 | A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation... |
| CVE-2023-28906 | HIGH | 7.8 | 0.7% | Jun 28, 2025 | A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the syst... |
| CVE-2023-28905 | HIGH | 8 | 0.4% | Jun 28, 2025 | A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitr... |
| CVE-2023-25998 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now