2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53039HIGH7.8In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: ipc: Fix potential use-after-fr...
CVE-2023-53038MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check kzalloc() in lpfc_sli4_cgn_params...
CVE-2023-53037HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Bad drive in topology results kernel ...
CVE-2023-53036MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix call trace warning and hang when re...
CVE-2023-53035HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_cop...
CVE-2023-46669HIGH7.1Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead t...
CVE-2023-4533Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. It was assigned as a d...
CVE-2023-45721MEDIUM5.3Insufficient default configuration in HCL Leap allows anonymous access to directory information.
CVE-2023-37535MEDIUM6.1Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
CVE-2023-37517HIGH7.5Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2023-4377Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-42404CRITICAL9.8OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
CVE-2023-35817CRITICAL9.8DevExpress before 23.1.3 allows AsyncDownloader SSRF.
CVE-2023-35816MEDIUM5.3DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
CVE-2023-35815CRITICAL9.8DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
CVE-2023-35814CRITICAL9.8DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
CVE-2023-37516LOW3.2Missing "no cache" headers in HCL Leap permits user directory information to be cached.
CVE-2023-45720MEDIUM5.3Insufficient default configuration in HCL Leap allows anonymous access to directory information.
CVE-2023-37534MEDIUM6.1Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
CVE-2023-44755CRITICAL9.8Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacc...
CVE-2023-44753MEDIUM6.1A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitra...
CVE-2023-44752CRITICAL9.8An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET...
CVE-2023-43958CRITICAL9.8An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management ...
CVE-2023-43378MEDIUM6.1A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTM...
CVE-2023-30421LOW2.9mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 88911...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now