2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49034MEDIUM6.1Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a cr...
CVE-2023-46967MEDIUM6.1Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to e...
CVE-2023-52435MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once ag...
CVE-2023-52434HIGH8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_conte...
CVE-2023-51447MEDIUM5.4Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the ...
CVE-2023-48220HIGH7.4Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_in...
CVE-2023-47635MEDIUM5.7Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the ...
CVE-2023-45318CRITICAL9.8A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit...
CVE-2023-39541MEDIUM5.9A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06...
CVE-2023-39540MEDIUM5.9A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06...
CVE-2023-38562CRITICAL9.1A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01...
CVE-2023-50306LOW3.3IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM...
CVE-2023-42791HIGH8.8A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4...
CVE-2023-52433HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new ele...
CVE-2023-7245HIGH7.8The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which all...
CVE-2023-51770HIGH7.5Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1....
CVE-2023-50270MEDIUM6.5Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. ...
CVE-2023-49250HIGH7.3Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attac...
CVE-2023-49109CRITICAL9.8Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1....
CVE-2023-44308MEDIUM6.1Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA thro...
CVE-2023-5190MEDIUM6.1Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101,...
CVE-2023-6764HIGH8.1 A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions f...
CVE-2023-6399MEDIUM6.5A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firm...
CVE-2023-6398HIGH7.2A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions fr...
CVE-2023-6397MEDIUM5.3 A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now