2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23364CRITICAL9.8A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploi...
CVE-2023-23363CRITICAL9.8A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploit...
CVE-2023-23362HIGH8.8An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit...
CVE-2023-31719CRITICAL9.8FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
CVE-2023-31718HIGH7.5FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
CVE-2023-31717HIGH7.5A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
CVE-2023-31716HIGH7.5FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
CVE-2023-5068HIGH7.8Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file....
CVE-2023-4504HIGH7Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are sus...
CVE-2023-43128CRITICAL9.8D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of ...
CVE-2023-41616MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 ...
CVE-2023-41614MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allow...
CVE-2023-42261HIGH7.5Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is th...
CVE-2023-38344MEDIUM6.5An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFil...
CVE-2023-38343HIGH7.5An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022...
CVE-2023-42482HIGH7.5Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.
CVE-2023-34576CRITICAL9.8SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitra...
CVE-2023-42280HIGH7.5mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not v...
CVE-2023-41993HIGH8.8The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to...
CVE-2023-41992HIGH7.8The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO...
CVE-2023-41991MEDIUM5.5A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal...
CVE-2023-42810CRITICAL9.8systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injecti...
CVE-2023-42279CRITICAL9.8Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
CVE-2023-42807CRITICAL9.8Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there w...
CVE-2023-42806MEDIUM6.5Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{ci...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now