2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34179 | HIGH | 7.2 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Gr... |
| CVE-2023-32508 | HIGH | 7.2 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Or... |
| CVE-2023-32121 | HIGH | 7.2 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zer... |
| CVE-2023-25990 | HIGH | 8.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ... |
| CVE-2023-25800 | HIGH | 8.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ... |
| CVE-2023-5088 | HIGH | 7 | 0.2% | Nov 3, 2023 | A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset... |
| CVE-2023-46947 | HIGH | 8.8 | 1.3% | Nov 3, 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. |
| CVE-2023-4769 | HIGH | 8.8 | 3.3% | Nov 3, 2023 | A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfi... |
| CVE-2023-4043 | HIGH | 7.5 | 0.8% | Nov 3, 2023 | In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exp... |
| CVE-2023-1476 | HIGH | 7 | 0.2% | Nov 3, 2023 | A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue ... |
| CVE-2023-5824 | HIGH | 7.5 | 5.2% | Nov 3, 2023 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. Howeve... |
| CVE-2023-46848 | HIGH | 7.5 | 10.2% | Nov 3, 2023 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques... |
| CVE-2023-46847 | HIGH | 7.5 | 88.4% | Nov 3, 2023 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to... |
| CVE-2023-1194 | HIGH | 8.1 | 1.1% | Nov 3, 2023 | An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samb... |
| CVE-2023-41357 | HIGH | 8.8 | 0.6% | Nov 3, 2023 | Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filte... |
| CVE-2023-41344 | HIGH | 7.5 | 1.0% | Nov 3, 2023 | NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic... |
| CVE-2023-41353 | HIGH | 8.8 | 0.5% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user p... |
| CVE-2023-41352 | HIGH | 7.2 | 1.2% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with adm... |
| CVE-2023-45024 | HIGH | 7.5 | 0.6% | Nov 3, 2023 | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transac... |
| CVE-2023-44271 | HIGH | 7.5 | 1.0% | Nov 3, 2023 | An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to proce... |
| CVE-2023-43665 | HIGH | 7.5 | 1.2% | Nov 3, 2023 | In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words(... |
| CVE-2023-41914 | HIGH | 7 | 0.2% | Nov 3, 2023 | SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership... |
| CVE-2023-41348 | HIGH | 8.8 | 1.3% | Nov 3, 2023 | ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi... |
| CVE-2023-41347 | HIGH | 8.8 | 1.3% | Nov 3, 2023 | ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi... |
| CVE-2023-41346 | HIGH | 8.8 | 1.2% | Nov 3, 2023 | ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now