2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-36027MEDIUM6.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-46735MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6....
CVE-2023-46734MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2...
CVE-2023-46733MEDIUM6.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5...
CVE-2023-4949MEDIUM6.7An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition...
CVE-2023-6075MEDIUM6.1A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is ...
CVE-2023-47119MEDIUM6.1Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version...
CVE-2023-46130MEDIUM5.4Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version...
CVE-2023-45806MEDIUM5.4Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version...
CVE-2023-47164MEDIUM6.1Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute a...
CVE-2023-6073MEDIUM6.3Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of ...
CVE-2023-45167MEDIUM5.5IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial...
CVE-2023-46729MEDIUM6.1sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sendin...
CVE-2023-5549MEDIUM5.3Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par...
CVE-2023-5548MEDIUM5.3Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
CVE-2023-5547MEDIUM6.1The course upload preview contained an XSS risk for users uploading unsafe data.
CVE-2023-5546MEDIUM5.4ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
CVE-2023-5545MEDIUM5.3H5P metadata automatically populated the author with the user's username, which could be sensitive information.
CVE-2023-5544MEDIUM5.4Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR ris...
CVE-2023-5542MEDIUM4.3Students in "Only see own membership" groups could see other students in the group, which should be hidden.
CVE-2023-5541MEDIUM6.1The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
CVE-2023-39198MEDIUM6.4A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the q...
CVE-2023-45885MEDIUM5.4Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary ...
CVE-2023-45884MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view se...
CVE-2023-45284MEDIUM5.3On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now