2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6238MEDIUM6.7A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user cou...
CVE-2023-48299MEDIUM5.3TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to versio...
CVE-2023-47643MEDIUM5.3SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection...
CVE-2023-20265MEDIUM5.4A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated,...
CVE-2023-20208MEDIUM4.8A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond...
CVE-2023-6211MEDIUM6.5If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker...
CVE-2023-6210MEDIUM6.5When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable...
CVE-2023-6209MEDIUM6.5Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be...
CVE-2023-6206MEDIUM5.4The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prom...
CVE-2023-6205MEDIUM6.5It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to a...
CVE-2023-6204MEDIUM6.5On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak m...
CVE-2023-49061MEDIUM6.1An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerab...
CVE-2023-48124MEDIUM5.4Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email...
CVE-2023-28802MEDIUM5.4An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to d...
CVE-2023-5599MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x thr...
CVE-2023-5598MEDIUM5.4Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ...
CVE-2023-5553MEDIUM6.8During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t...
CVE-2023-46935MEDIUM5.4eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in u...
CVE-2023-21416MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable t...
CVE-2023-6144MEDIUM4.8Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use...
CVE-2023-6142MEDIUM5.4Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. Wi...
CVE-2023-6199MEDIUM6.5Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulne...
CVE-2023-6178MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing applicatio...
CVE-2023-6062MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on t...
CVE-2023-47311MEDIUM6.1An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now