2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52586 | HIGH | 7 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add mutex lock in control vblank irq ... |
| CVE-2023-52585 | MEDIUM | 5.5 | 0.3% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu... |
| CVE-2023-52584 | LOW | 3.8 | 0.6% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif ... |
| CVE-2023-52583 | MEDIUM | 5.5 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix deadlock or deadcode of misusing dget() ... |
| CVE-2023-49977 | MEDIUM | 5.4 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49976 | MEDIUM | 5.4 | 0.5% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49974 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49973 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49971 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-33677 | HIGH | 7.5 | 0.4% | Mar 6, 2024 | Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=... |
| CVE-2023-43318 | HIGH | 8.8 | 1.1% | Mar 6, 2024 | TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of... |
| CVE-2023-38946 | HIGH | 8.8 | 0.8% | Mar 6, 2024 | An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access cont... |
| CVE-2023-38945 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Mul... |
| CVE-2023-38944 | CRITICAL | 9.8 | 15.5% | Mar 6, 2024 | An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers t... |
| CVE-2023-48644 | MEDIUM | 6.1 | 0.3% | Mar 5, 2024 | An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feat... |
| CVE-2023-45290 | MEDIUM | 6.5 | 1.2% | Mar 5, 2024 | When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, R... |
| CVE-2023-45289 | MEDIUM | 4.3 | 1.1% | Mar 5, 2024 | When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http... |
| CVE-2023-26282 | MEDIUM | 4.2 | 0.2% | Mar 5, 2024 | IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy... |
| CVE-2023-25681 | MEDIUM | 6.5 | 0.6% | Mar 5, 2024 | LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authentic... |
| CVE-2023-7103 | CRITICAL | 9.8 | 0.6% | Mar 5, 2024 | Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authen... |
| CVE-2023-5457 | CRITICAL | 9.8 | 0.6% | Mar 5, 2024 | A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web app... |
| CVE-2023-45600 | CRITICAL | 9.8 | 0.4% | Mar 5, 2024 | A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” ... |
| CVE-2023-45599 | HIGH | 8.8 | 0.2% | Mar 5, 2024 | A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality... |
| CVE-2023-45598 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allow... |
| CVE-2023-45597 | CRITICAL | 9 | 0.4% | Mar 5, 2024 | A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now