2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-54223CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix invalid buffer access for legac...
CVE-2023-54203CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr ...
CVE-2023-54184CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsit: Free cmds before session free...
CVE-2023-54094CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: prevent skb corruption on frag list segmentati...
CVE-2023-54090CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix panic during XDP_TX with > 64 CPUs Comm...
CVE-2023-54076CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix missed ses refcounting Use new ci...
CVE-2023-53996CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: x86/sev: Make enc_dec_hypercall() accept a size ins...
CVE-2023-53867CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimmin...
CVE-2023-53982CRITICAL9.3PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote at...
CVE-2023-53980CRITICAL9.8ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by mani...
CVE-2023-53975CRITICAL9.3Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database...
CVE-2023-53969CRITICAL9.3Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authenti...
CVE-2023-53968CRITICAL9.8Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authenti...
CVE-2023-53967CRITICAL9.3Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the ...
CVE-2023-53966CRITICAL9.8SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory sta...
CVE-2023-53964CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endp...
CVE-2023-53963CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote att...
CVE-2023-53960CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mech...
CVE-2023-53955CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to b...
CVE-2023-53959CRITICAL9.8FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placin...
CVE-2023-53951CRITICAL9.8Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key im...
CVE-2023-53950CRITICAL9.8InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file ...
CVE-2023-53948CRITICAL9.8Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows ...
CVE-2023-53942CRITICAL9.4File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious ...
CVE-2023-53941CRITICAL9.8EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now