2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6652CRITICAL9.8A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vuln...
CVE-2023-6651CRITICAL9.8A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unkn...
CVE-2023-6650MEDIUM6.1A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issu...
CVE-2023-6649MEDIUM6.1A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problema...
CVE-2023-6648CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. Th...
CVE-2023-6647CRITICAL9.8A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unkn...
CVE-2023-50431MEDIUM5.5sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an inform...
CVE-2023-6646MEDIUM5.4A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipu...
CVE-2023-50430MEDIUM6.4The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Pr...
CVE-2023-50429CRITICAL9.1IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.
CVE-2023-50428MEDIUM5.3In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obf...
CVE-2023-47254CRITICAL9.8An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbit...
CVE-2023-6120LOW2.7The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2...
CVE-2023-5756HIGH8.8The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to...
CVE-2023-46932CRITICAL9.8Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitra...
CVE-2023-28874MEDIUM6.1The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary site...
CVE-2023-28873MEDIUM5.4An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown edito...
CVE-2023-28871MEDIUM4.3Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the oper...
CVE-2023-28870MEDIUM6.5Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to ...
CVE-2023-28869MEDIUM6.5Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on ...
CVE-2023-28868HIGH8.1Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operati...
CVE-2023-47465MEDIUM5.5An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read fun...
CVE-2023-47722MEDIUM5.5IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM...
CVE-2023-28527MEDIUM5.5 IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds chec...
CVE-2023-28526MEDIUM5.5 IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bound...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now