2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32256HIGH7.5A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in mult...
CVE-2023-44976LOW3.2Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified...
CVE-2023-32251LOW3.7A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control d...
CVE-2023-41674Rejected reason: Not used
CVE-2023-2593MEDIUM5.9A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory relea...
CVE-2023-53161MEDIUM5.3The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
CVE-2023-53160MEDIUM5.3The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVE-2023-53159CRITICAL9.1The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho...
CVE-2023-53158MEDIUM4.1The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IF...
CVE-2023-53157HIGH7.5The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UD...
CVE-2023-53156MEDIUM5.3The transpose crate before 0.2.3 for Rust allows an integer overflow via input_width and input_height arguments.
CVE-2023-2274Rejected reason: This CVE assignment was considered invalid after investigation.
CVE-2023-53155HIGH7.2goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.
CVE-2023-7306HIGH7.5The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi...
CVE-2023-47356HIGH8.8Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th...
CVE-2023-41566HIGH8.1OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend...
CVE-2023-39339MEDIUM4.9A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can per...
CVE-2023-39338MEDIUM6.8Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized ...
CVE-2023-38036CRITICAL9.8A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to c...
CVE-2023-38329MEDIUM6.1An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in cale...
CVE-2023-38327MEDIUM5.3An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php...
CVE-2023-50458MEDIUM4.3In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
CVE-2023-43039MEDIUM6.1IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2023-52236HIGH7A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All...
CVE-2023-51232HIGH7.5Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now