2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6840MEDIUM6.7An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16...
CVE-2023-6736MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting...
CVE-2023-6536HIGH7.5A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se...
CVE-2023-6535HIGH7.5A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se...
CVE-2023-6356HIGH7.5A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se...
CVE-2023-38995CRITICAL9.8An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.
CVE-2023-47700HIGH7.5IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote at...
CVE-2023-43017HIGH7.2IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that ...
CVE-2023-38369HIGH7.5IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong p...
CVE-2023-32330CRITICAL9.8IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to ...
CVE-2023-32328CRITICAL9.8IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attac...
CVE-2023-31002MEDIUM5.5IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that c...
CVE-2023-39196MEDIUM5.3Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern...
CVE-2023-51437HIGH7.4Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge...
CVE-2023-46914CRITICAL9.8SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attacke...
CVE-2023-40355MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0...
CVE-2023-6388MEDIUM5Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because ...
CVE-2023-45735HIGH8 A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affec...
CVE-2023-45227MEDIUM5.4 An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr...
CVE-2023-45222MEDIUM5.4 An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript ...
CVE-2023-45213MEDIUM6.5 A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a...
CVE-2023-42765MEDIUM5.4 An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si...
CVE-2023-40544MEDIUM5.7 An attacker with access to the network where the affected devices are located could maliciously actions to ob...
CVE-2023-40143MEDIUM5.4 An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary...
CVE-2023-38579HIGH8.8 The cross-site request forgery token in the request may be predictable or easily guessable allowing attacke...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now