2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6584HIGH7.5The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only kno...
CVE-2023-51518CRITICAL9.8Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserial...
CVE-2023-50379HIGH8.8Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fi...
CVE-2023-7033MEDIUM5.3Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU ...
CVE-2023-41506CRITICAL9.8An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PH...
CVE-2023-36237HIGH8.8Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a cr...
CVE-2023-52474HIGH7.8In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iove...
CVE-2023-5775LOW2.7The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up t...
CVE-2023-52473MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix NULL pointer dereference in zone...
CVE-2023-52472MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: rsa - add a check for allocation failure S...
CVE-2023-52471MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: Fix some null pointer dereference issues in ic...
CVE-2023-52470MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check the alloc_workqueue return value ...
CVE-2023-52469HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_po...
CVE-2023-52468HIGH7.8In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The ...
CVE-2023-52467MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_sys...
CVE-2023-52466Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52465MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: power: supply: Fix null pointer dereference in smb2...
CVE-2023-49960HIGH7.5In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmwa...
CVE-2023-49959CRITICAL9.8In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the fir...
CVE-2023-49114MEDIUM6.7A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local ...
CVE-2023-43051MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2023-38359MEDIUM6.1IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2023-32344MEDIUM4.3IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify th...
CVE-2023-30996MEDIUM5.3IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in ...
CVE-2023-51394HIGH7.5High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now