2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6840 | MEDIUM | 6.7 | 0.6% | Feb 7, 2024 | An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16... |
| CVE-2023-6736 | MEDIUM | 6.5 | 0.6% | Feb 7, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting... |
| CVE-2023-6536 | HIGH | 7.5 | 1.5% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-6535 | HIGH | 7.5 | 1.5% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-6356 | HIGH | 7.5 | 1.4% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-38995 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command. |
| CVE-2023-47700 | HIGH | 7.5 | 0.5% | Feb 7, 2024 | IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote at... |
| CVE-2023-43017 | HIGH | 7.2 | 0.6% | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that ... |
| CVE-2023-38369 | HIGH | 7.5 | 0.5% | Feb 7, 2024 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong p... |
| CVE-2023-32330 | CRITICAL | 9.8 | 0.9% | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to ... |
| CVE-2023-32328 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attac... |
| CVE-2023-31002 | MEDIUM | 5.5 | 0.1% | Feb 7, 2024 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that c... |
| CVE-2023-39196 | MEDIUM | 5.3 | 0.8% | Feb 7, 2024 | Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern... |
| CVE-2023-51437 | HIGH | 7.4 | 0.8% | Feb 7, 2024 | Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge... |
| CVE-2023-46914 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attacke... |
| CVE-2023-40355 | MEDIUM | 5.4 | 1.1% | Feb 7, 2024 | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0... |
| CVE-2023-6388 | MEDIUM | 5 | 0.5% | Feb 7, 2024 | Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because ... |
| CVE-2023-45735 | HIGH | 8 | 0.5% | Feb 6, 2024 | A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affec... |
| CVE-2023-45227 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr... |
| CVE-2023-45222 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript ... |
| CVE-2023-45213 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a... |
| CVE-2023-42765 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si... |
| CVE-2023-40544 | MEDIUM | 5.7 | 0.2% | Feb 6, 2024 | An attacker with access to the network where the affected devices are located could maliciously actions to ob... |
| CVE-2023-40143 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary... |
| CVE-2023-38579 | HIGH | 8.8 | 0.2% | Feb 6, 2024 | The cross-site request forgery token in the request may be predictable or easily guessable allowing attacke... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now