2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53750In the Linux kernel, the following vulnerability has been resolved: pinctrl: freescale: Fix a memory out of bounds when...
CVE-2023-53749Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-53748HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix potential array out-of...
CVE-2023-53747HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vc_screen: reload load of struct vc_data pointer in...
CVE-2023-53746In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device dri...
CVE-2023-53745In the Linux kernel, the following vulnerability has been resolved: um: vector: Fix memory leak in vector_config If th...
CVE-2023-53744In the Linux kernel, the following vulnerability has been resolved: soc: ti: pm33xx: Fix refcount leak in am33xx_pm_pro...
CVE-2023-53743In the Linux kernel, the following vulnerability has been resolved: PCI: Free released resource after coalescing relea...
CVE-2023-53742In the Linux kernel, the following vulnerability has been resolved: kcsan: Avoid READ_ONCE() in read_instrumented_memor...
CVE-2023-53735MEDIUM5.3WEBIGniter 28.7.23 contains a cross-site scripting vulnerability in the user creation process that allows unauthenticate...
CVE-2023-53734HIGH8.7dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive...
CVE-2023-7330CRITICAL9.3Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php....
CVE-2023-7328MEDIUM5.3Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user manageme...
CVE-2023-7329HIGH8.7Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulne...
CVE-2023-7327HIGH8.7Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation ...
CVE-2023-7326HIGH8.7The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in que...
CVE-2023-43000HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16....
CVE-2023-7325CRITICAL9.3Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request fo...
CVE-2023-7323MEDIUM5.4Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. In...
CVE-2023-7322HIGH8.1Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the requir...
CVE-2023-7321MEDIUM5.4Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untruste...
CVE-2023-7319MEDIUM5.4Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calcula...
CVE-2023-7318MEDIUM5.4Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expans...
CVE-2023-7317HIGH8.8Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, lo...
CVE-2023-7316MEDIUM5.4Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insuff...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now