2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53039 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: ipc: Fix potential use-after-fr... |
| CVE-2023-53038 | MEDIUM | 5.5 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check kzalloc() in lpfc_sli4_cgn_params... |
| CVE-2023-53037 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Bad drive in topology results kernel ... |
| CVE-2023-53036 | MEDIUM | 5.5 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix call trace warning and hang when re... |
| CVE-2023-53035 | HIGH | 7.1 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_cop... |
| CVE-2023-46669 | HIGH | 7.1 | 0.2% | May 1, 2025 | Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead t... |
| CVE-2023-4533 | — | — | — | Apr 30, 2025 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. It was assigned as a d... |
| CVE-2023-45721 | MEDIUM | 5.3 | 0.3% | Apr 30, 2025 | Insufficient default configuration in HCL Leap allows anonymous access to directory information. |
| CVE-2023-37535 | MEDIUM | 6.1 | 0.2% | Apr 30, 2025 | Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters. |
| CVE-2023-37517 | HIGH | 7.5 | 0.2% | Apr 30, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
| CVE-2023-4377 | — | — | — | Apr 29, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-42404 | CRITICAL | 9.8 | 0.3% | Apr 28, 2025 | OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. |
| CVE-2023-35817 | CRITICAL | 9.8 | 0.3% | Apr 28, 2025 | DevExpress before 23.1.3 allows AsyncDownloader SSRF. |
| CVE-2023-35816 | MEDIUM | 5.3 | 0.4% | Apr 28, 2025 | DevExpress before 23.1.3 allows arbitrary TypeConverter conversion. |
| CVE-2023-35815 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. |
| CVE-2023-35814 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. |
| CVE-2023-37516 | LOW | 3.2 | 0.1% | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits user directory information to be cached. |
| CVE-2023-45720 | MEDIUM | 5.3 | 0.3% | Apr 24, 2025 | Insufficient default configuration in HCL Leap allows anonymous access to directory information. |
| CVE-2023-37534 | MEDIUM | 6.1 | 0.2% | Apr 24, 2025 | Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. |
| CVE-2023-44755 | CRITICAL | 9.8 | 0.5% | Apr 22, 2025 | Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacc... |
| CVE-2023-44753 | MEDIUM | 6.1 | 0.3% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitra... |
| CVE-2023-44752 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET... |
| CVE-2023-43958 | CRITICAL | 9.8 | 1.0% | Apr 22, 2025 | An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management ... |
| CVE-2023-43378 | MEDIUM | 6.1 | 0.3% | Apr 22, 2025 | A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2023-30421 | LOW | 2.9 | 0.1% | Apr 19, 2025 | mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 88911... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now