2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45596MEDIUM5.3A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web applic...
CVE-2023-45595HIGH8.8A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of t...
CVE-2023-45594MEDIUM6.8A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a ...
CVE-2023-45593MEDIUM6.8A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling...
CVE-2023-45592CRITICAL9.8A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary bein...
CVE-2023-45591HIGH8.8A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a re...
CVE-2023-5456CRITICAL9.8A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote u...
CVE-2023-42419LOW3.8Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compil...
CVE-2023-52432HIGH7.1Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attacker...
CVE-2023-49970CRITICAL9.8Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /custome...
CVE-2023-49969MEDIUM4.3Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup...
CVE-2023-49968HIGH7.3Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup...
CVE-2023-49548HIGH8.8Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /custom...
CVE-2023-49547CRITICAL9.8Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /custom...
CVE-2023-49546HIGH8.8Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_...
CVE-2023-41829MEDIUM5An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious,...
CVE-2023-41827MEDIUM5.1An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, loca...
CVE-2023-6068LOW3.1On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may...
CVE-2023-32331HIGH7.5IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a deni...
CVE-2023-38360MEDIUM6.1IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2023-5451MEDIUM6.1Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Ma...
CVE-2023-38362MEDIUM5.3IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTT...
CVE-2023-6241HIGH7Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GP...
CVE-2023-43553CRITICAL9.8Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
CVE-2023-43552CRITICAL9.8Memory corruption while processing MBSSID beacon containing several subelement IE.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now