2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-51310MEDIUM4.3A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 al...
CVE-2023-51309MEDIUM4.3A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to s...
CVE-2023-51308MEDIUM6.1PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugi...
CVE-2023-51306MEDIUM5.4PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" ...
CVE-2023-51305MEDIUM5.4PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, plugin...
CVE-2023-51303MEDIUM6.1PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, p...
CVE-2023-51300MEDIUM6.1PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sm...
CVE-2023-51299MEDIUM6.1PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_countr...
CVE-2023-51298MEDIUM4.7PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute ...
CVE-2023-51297MEDIUM6.5A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send...
CVE-2023-51296MEDIUM6.1PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plu...
CVE-2023-34404MEDIUM4.9Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins a...
CVE-2023-34403MEDIUM4.9Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins an...
CVE-2023-48366MEDIUM5.6Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user...
CVE-2023-32277MEDIUM6.1Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticat...
CVE-2023-49780MEDIUM6.1Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on ...
CVE-2023-20508MEDIUM5Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory locat...
CVE-2023-31352MEDIUM6A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in los...
CVE-2023-20582MEDIUM5.3Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table...
CVE-2023-20515MEDIUM5.7Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory,...
CVE-2023-40721MEDIUM6.7A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged atta...
CVE-2023-37482MEDIUM6.9The login functionality of the web server in affected devices does not normalize the response times of login attempts. A...
CVE-2023-52925MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't fail inserts if duplica...
CVE-2023-52924MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements d...
CVE-2023-52164MEDIUM5.1access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now