2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-52382Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6877MEDIUM5.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-5912MEDIUM6.7 A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker ...
CVE-2023-4605MEDIUM6.5 A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoin...
CVE-2023-25494MEDIUM6.7 A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could a...
CVE-2023-25493MEDIUM6.7A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and Th...
CVE-2023-31028LOW2.8 NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable a...
CVE-2023-48426CRITICAL10u-boot bug that allows for u-boot shell and interrupt over UART
CVE-2023-49965MEDIUM6.8SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.
CVE-2023-5692MEDIUM5.3WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect...
CVE-2023-6523HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. ...
CVE-2023-6522HIGH7.2Incorrect Use of Privileged APIs vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users. Thi...
CVE-2023-52235HIGH8.8SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow ...
CVE-2023-5973MEDIUM4.3Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user...
CVE-2023-45288HIGH7.5An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONT...
CVE-2023-38709HIGH7.3Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP r...
CVE-2023-3454CRITICAL9.8Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to e...
CVE-2023-36645CRITICAL9.8SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow compone...
CVE-2023-36644MEDIUM5.3Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the ...
CVE-2023-36643MEDIUM5.3Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop v...
CVE-2023-25200MEDIUM4.7An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote ...
CVE-2023-25199MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 t...
CVE-2023-52043HIGH8.1An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wirel...
CVE-2023-52641MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the ...
CVE-2023-52640HIGH7.1In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now