2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0989MEDIUM5.7An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior t...
CVE-2023-44466HIGH8.8An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness erro...
CVE-2023-30591HIGH7.5Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.sta...
CVE-2023-44464HIGH7.8pretix before 2023.7.2 allows Pillow to parse EPS files.
CVE-2023-26148MEDIUM5.3All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set requ...
CVE-2023-26147MEDIUM6.1All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to...
CVE-2023-26146MEDIUM6.1All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name...
CVE-2023-5077HIGH7.5The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio...
CVE-2023-3775MEDIUM4.9A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac...
CVE-2023-43654CRITICAL9.8TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper...
CVE-2023-44174MEDIUM5.4Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability. ...
CVE-2023-44168Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44167Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44166CRITICAL9.8The 'age' parameter of the process_registration.php resource does not validate the characters received and they are se...
CVE-2023-44165Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-44164CRITICAL9.8The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent un...
CVE-2023-44163CRITICAL9.8The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent ...
CVE-2023-43739CRITICAL9.8The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfilter...
CVE-2023-43662HIGH8.6ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endp...
CVE-2023-43014HIGH8.8Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'la...
CVE-2023-5185HIGH8.8Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of p...
CVE-2023-5053CRITICAL9.8Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is...
CVE-2023-5004CRITICAL9.8Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is...
CVE-2023-4316HIGH7.5Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating ema...
CVE-2023-44173MEDIUM5.4Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now