2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5500HIGH8.8This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code...
CVE-2023-49355HIGH7.5decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" inpu...
CVE-2023-6181CRITICAL9.8An oversight in BCB handling of reboot reason that allows for persistent code execution
CVE-2023-48425CRITICAL9.8U-Boot vulnerability resulting in persistent Code Execution 
CVE-2023-48424CRITICAL9.8U-Boot shell vulnerability resulting in Privilege escalation in a production device
CVE-2023-48417CRITICAL9.8Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
CVE-2023-6659HIGH7.5A vulnerability, which was classified as critical, has been found in Campcodes Web-Based Student Clearance System 1.0. T...
CVE-2023-50465MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by ...
CVE-2023-6658CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerabil...
CVE-2023-50463MEDIUM6.5The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows att...
CVE-2023-6657CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affec...
CVE-2023-6656HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has be...
CVE-2023-50457MEDIUM4.3An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge bas...
CVE-2023-50456MEDIUM5.3An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails ...
CVE-2023-50455HIGH7.5An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature...
CVE-2023-50454MEDIUM5.9An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to exte...
CVE-2023-50453MEDIUM5.3An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This ...
CVE-2023-5870MEDIUM4.4A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logic...
CVE-2023-5869HIGH8.8A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overfl...
CVE-2023-5868MEDIUM4.3A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by ex...
CVE-2023-50449HIGH7.5JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey...
CVE-2023-50446HIGH7.8An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow an...
CVE-2023-6655CRITICAL9.8A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some ...
CVE-2023-6654HIGH8.8A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown...
CVE-2023-6653MEDIUM4.3A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problemat...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now