2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-47799HIGH7.5Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used...
CVE-2023-3867HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup k...
CVE-2023-3865HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_s...
CVE-2023-43692HIGH7.5An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of...
CVE-2023-45584HIGH7.2A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0....
CVE-2023-41532HIGH8.8Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i...
CVE-2023-41531HIGH8.8Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user...
CVE-2023-41524HIGH8.8Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet...
CVE-2023-41523HIGH8.8Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par...
CVE-2023-41522HIGH8.8Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden...
CVE-2023-41521HIGH8.8Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio...
CVE-2023-41520HIGH8.8Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA...
CVE-2023-32256HIGH7.5A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in mult...
CVE-2023-53157HIGH7.5The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UD...
CVE-2023-53155HIGH7.2goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.
CVE-2023-7306HIGH7.5The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi...
CVE-2023-47356HIGH8.8Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th...
CVE-2023-41566HIGH8.1OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend...
CVE-2023-52236HIGH7A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All...
CVE-2023-51232HIGH7.5Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive i...
CVE-2023-28910HIGH8A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled a...
CVE-2023-28909HIGH8A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation...
CVE-2023-28906HIGH7.8A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the syst...
CVE-2023-28905HIGH8A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitr...
CVE-2023-25998HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now