2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46847HIGH7.5Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to...
CVE-2023-46846MEDIUM5.3SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform R...
CVE-2023-42670MEDIUM6.5A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiat...
CVE-2023-1194HIGH8.1An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samb...
CVE-2023-5948MEDIUM5.5Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
CVE-2023-5763CRITICAL9.8In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote ...
CVE-2023-41357HIGH8.8Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filte...
CVE-2023-41356MEDIUM6.5NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic...
CVE-2023-41344HIGH7.5NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic...
CVE-2023-41355CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An...
CVE-2023-41354MEDIUM5.3Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated ...
CVE-2023-41353HIGH8.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user p...
CVE-2023-41352HIGH7.2Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with adm...
CVE-2023-41351CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote att...
CVE-2023-46817CRITICAL9.8An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not pro...
CVE-2023-46517Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-45362MEDIUM4.3An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1....
CVE-2023-45360MEDIUM5.4An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. Ther...
CVE-2023-45024HIGH7.5Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transac...
CVE-2023-44271HIGH7.5An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to proce...
CVE-2023-43982CRITICAL9.8Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) ...
CVE-2023-43665HIGH7.5In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words(...
CVE-2023-41914HIGH7SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership...
CVE-2023-41350CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication a...
CVE-2023-41348HIGH8.8ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now