2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50275HIGH7.5HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
CVE-2023-50274HIGH7.8HPE OneView may allow command injection with local privilege escalation.
CVE-2023-49657MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with...
CVE-2023-49783MEDIUM4.3Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch p...
CVE-2023-48714MEDIUM4.3Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to vers...
CVE-2023-44401MEDIUM5.3The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3....
CVE-2023-51043HIGH7In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a no...
CVE-2023-51042HIGH7.8In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-a...
CVE-2023-46343MEDIUM5.5In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
CVE-2023-39197HIGH7.5An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This fla...
CVE-2023-42937MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 an...
CVE-2023-42935MEDIUM5.5An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A loc...
CVE-2023-42915Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-42888MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS V...
CVE-2023-42887MEDIUM6.3An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS S...
CVE-2023-42881HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may l...
CVE-2023-40528MEDIUM5.5This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, i...
CVE-2023-47141MEDIUM6.5IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT p...
CVE-2023-24135HIGH7.8Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the fu...
CVE-2023-7194MEDIUM6.1The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the ...
CVE-2023-7170MEDIUM6.1The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in...
CVE-2023-7082HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip...
CVE-2023-6626MEDIUM4.8The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which...
CVE-2023-6625MEDIUM4.3The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquir...
CVE-2023-6456MEDIUM4.8The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow h...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now