2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45552MEDIUM6.5In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal th...
CVE-2023-44040MEDIUM6.1In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that...
CVE-2023-44038MEDIUM6.5In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about ...
CVE-2023-35812MEDIUM5.3An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete f...
CVE-2023-44039CRITICAL9.1In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifi...
CVE-2023-5755Rejected reason: **REJECT** Duplicate of CVE-2023-46784. Please refer to CVE-2023-46784.
CVE-2023-52639MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: fix race during shadow creation R...
CVE-2023-52638MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: j1939: prevent deadlock by changing j1939_sock...
CVE-2023-52637HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: j1939: Fix UAF in j1939_sk_match_filter during...
CVE-2023-52296MEDIUM5.3IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying ...
CVE-2023-38729MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive inform...
CVE-2023-25699CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper...
CVE-2023-35764MEDIUM5.3Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated atta...
CVE-2023-34423MEDIUM6.1Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an...
CVE-2023-50313MEDIUM6.5IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections ca...
CVE-2023-6951MEDIUM6.6A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remot...
CVE-2023-6950LOW3An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an ...
CVE-2023-6949MEDIUM5.2A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on t...
CVE-2023-6948LOW3A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on...
CVE-2023-51456MEDIUM6.8A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 c...
CVE-2023-51455MEDIUM6.8A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the por...
CVE-2023-51454MEDIUM6.8A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could a...
CVE-2023-51453LOW3A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 c...
CVE-2023-51452LOW3A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 c...
CVE-2023-52636MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: libceph: just wait for more data to be available on...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now