2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50378MEDIUM6.1Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be st...
CVE-2023-52497MEDIUM6.1In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently ERO...
CVE-2023-46951MEDIUM6.1Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive informatio...
CVE-2023-46950MEDIUM6.1Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive informatio...
CVE-2023-48674MEDIUM4.9Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the...
CVE-2023-39254HIGH7.3Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user ...
CVE-2023-52555MEDIUM6.1In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
CVE-2023-50312MEDIUM6.5IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbo...
CVE-2023-47716HIGH8.8IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges ...
CVE-2023-38366MEDIUM5.3IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse director...
CVE-2023-50324MEDIUM5.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an a...
CVE-2023-50305MEDIUM5.1IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by defaul...
CVE-2023-28949MEDIUM6.5IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an a...
CVE-2023-28525MEDIUM4.8IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2023-6132HIGH7.8 The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary cod...
CVE-2023-52485MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a comman...
CVE-2023-6090HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affec...
CVE-2023-52484MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Fix soft lockup triggered by arm...
CVE-2023-52483HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mctp: perform route lookups under a RCU read-side l...
CVE-2023-52482HIGH7.8In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors ...
CVE-2023-52481MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivil...
CVE-2023-52480HIGH7In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup an...
CVE-2023-52479HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop refe...
CVE-2023-52478MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver U...
CVE-2023-52477MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized B...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now