2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-34179HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Gr...
CVE-2023-32508HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Or...
CVE-2023-32121HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zer...
CVE-2023-25990HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ...
CVE-2023-25800HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ...
CVE-2023-5088HIGH7A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset...
CVE-2023-46947HIGH8.8Subrion 4.2.1 has a remote command execution vulnerability in the backend.
CVE-2023-4769HIGH8.8A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfi...
CVE-2023-4043HIGH7.5In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exp...
CVE-2023-1476HIGH7A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue ...
CVE-2023-5824HIGH7.5A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. Howeve...
CVE-2023-46848HIGH7.5Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques...
CVE-2023-46847HIGH7.5Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to...
CVE-2023-1194HIGH8.1An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samb...
CVE-2023-41357HIGH8.8Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filte...
CVE-2023-41344HIGH7.5NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic...
CVE-2023-41353HIGH8.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user p...
CVE-2023-41352HIGH7.2Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with adm...
CVE-2023-45024HIGH7.5Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transac...
CVE-2023-44271HIGH7.5An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to proce...
CVE-2023-43665HIGH7.5In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words(...
CVE-2023-41914HIGH7SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership...
CVE-2023-41348HIGH8.8ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi...
CVE-2023-41347HIGH8.8ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi...
CVE-2023-41346HIGH8.8ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now