2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42022MEDIUM5.4 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2023-42019MEDIUM5.9 IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp...
CVE-2023-42009MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-40699HIGH7.5 IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp...
CVE-2023-43015MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-38268HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec...
CVE-2023-26024MEDIUM6.5IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive informa...
CVE-2023-42006MEDIUM5.5IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information ...
CVE-2023-48893HIGH8.8SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Inj...
CVE-2023-48842CRITICAL9.8D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at...
CVE-2023-48813HIGH8.8Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/cu...
CVE-2023-4518HIGH7.5A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed ...
CVE-2023-49371CRITICAL9.8RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
CVE-2023-45168HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout comman...
CVE-2023-6461MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.
CVE-2023-5637HIGH7.5Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strin...
CVE-2023-5636CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. ...
CVE-2023-5635HIGH7.5Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ArslanSoft Education Portal allows Ac...
CVE-2023-5634CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Educati...
CVE-2023-28896LOW2.4Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is tran...
CVE-2023-28895MEDIUM6.8The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-cod...
CVE-2023-6449HIGH7.2The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation...
CVE-2023-5427HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2023-6033MEDIUM5.4Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 pr...
CVE-2023-5995HIGH7.5An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now