2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0775MEDIUM6.5An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to ...
CVE-2023-27008MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows r...
CVE-2023-0466MEDIUM5.3The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing ...
CVE-2023-0465MEDIUM5.3Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious C...
CVE-2023-25197MEDIUM6.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-25196MEDIUM4.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-25704MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugi...
CVE-2023-26924MEDIUM5.5LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the ...
CVE-2023-1637MEDIUM5.5A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 ...
CVE-2023-0326MEDIUM4.3An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where...
CVE-2023-28638MEDIUM5.9Snappier is a high performance C# implementation of the Snappy compression algorithm. This is a buffer overrun vulnerabi...
CVE-2023-28630MEDIUM4.4GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environm...
CVE-2023-28629MEDIUM5.4GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerabil...
CVE-2023-28628MEDIUM6.1lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an ...
CVE-2023-25878MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25877MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25876MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25875MEDIUM5.5Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could le...
CVE-2023-25263MEDIUM5.5In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attac...
CVE-2023-24366MEDIUM6.5An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HT...
CVE-2023-22251MEDIUM4.3Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vul...
CVE-2023-22250MEDIUM5.3Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vul...
CVE-2023-22249MEDIUM4.8Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting ...
CVE-2023-1079MEDIUM6.8A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconne...
CVE-2023-1076MEDIUM5.5A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now