2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-52586HIGH7In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add mutex lock in control vblank irq ...
CVE-2023-52585MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu...
CVE-2023-52584LOW3.8In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif ...
CVE-2023-52583MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ceph: fix deadlock or deadcode of misusing dget() ...
CVE-2023-49977MEDIUM5.4A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49976MEDIUM5.4A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49974MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49973MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-49971MEDIUM6.1A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip...
CVE-2023-33677HIGH7.5Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=...
CVE-2023-43318HIGH8.8TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of...
CVE-2023-38946HIGH8.8An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access cont...
CVE-2023-38945CRITICAL9.8Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Mul...
CVE-2023-38944CRITICAL9.8An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers t...
CVE-2023-48644MEDIUM6.1An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feat...
CVE-2023-45290MEDIUM6.5When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, R...
CVE-2023-45289MEDIUM4.3When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http...
CVE-2023-26282MEDIUM4.2IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy...
CVE-2023-25681MEDIUM6.5LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authentic...
CVE-2023-7103CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authen...
CVE-2023-5457CRITICAL9.8A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web app...
CVE-2023-45600CRITICAL9.8A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” ...
CVE-2023-45599HIGH8.8A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality...
CVE-2023-45598MEDIUM5.3A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allow...
CVE-2023-45597CRITICAL9A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now