2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0989 | MEDIUM | 5.7 | 0.4% | Sep 29, 2023 | An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior t... |
| CVE-2023-44466 | HIGH | 8.8 | 54.6% | Sep 29, 2023 | An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness erro... |
| CVE-2023-30591 | HIGH | 7.5 | 53.8% | Sep 29, 2023 | Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.sta... |
| CVE-2023-44464 | HIGH | 7.8 | 0.3% | Sep 29, 2023 | pretix before 2023.7.2 allows Pillow to parse EPS files. |
| CVE-2023-26148 | MEDIUM | 5.3 | 0.4% | Sep 29, 2023 | All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set requ... |
| CVE-2023-26147 | MEDIUM | 6.1 | 0.4% | Sep 29, 2023 | All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to... |
| CVE-2023-26146 | MEDIUM | 6.1 | 0.4% | Sep 29, 2023 | All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name... |
| CVE-2023-5077 | HIGH | 7.5 | 0.4% | Sep 29, 2023 | The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio... |
| CVE-2023-3775 | MEDIUM | 4.9 | 0.5% | Sep 29, 2023 | A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac... |
| CVE-2023-43654 | CRITICAL | 9.8 | 35.3% | Sep 28, 2023 | TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper... |
| CVE-2023-44174 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability. ... |
| CVE-2023-44168 | — | — | — | Sep 28, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44167 | — | — | — | Sep 28, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44166 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'age' parameter of the process_registration.php resource does not validate the characters received and they are se... |
| CVE-2023-44165 | — | — | — | Sep 28, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44164 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent un... |
| CVE-2023-44163 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent ... |
| CVE-2023-43739 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfilter... |
| CVE-2023-43662 | HIGH | 8.6 | 8.1% | Sep 28, 2023 | ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endp... |
| CVE-2023-43014 | HIGH | 8.8 | 0.6% | Sep 28, 2023 | Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'la... |
| CVE-2023-5185 | HIGH | 8.8 | 1.2% | Sep 28, 2023 | Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of p... |
| CVE-2023-5053 | CRITICAL | 9.8 | 0.9% | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is... |
| CVE-2023-5004 | CRITICAL | 9.8 | 0.9% | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is... |
| CVE-2023-4316 | HIGH | 7.5 | 0.8% | Sep 28, 2023 | Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating ema... |
| CVE-2023-44173 | MEDIUM | 5.4 | 0.3% | Sep 28, 2023 | Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now