2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45588HIGH7.8An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0....
CVE-2023-33300MEDIUM5.3A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and ear...
CVE-2023-52927HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_fin...
CVE-2023-48790HIGH8.8A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 t...
CVE-2023-42784CRITICAL9.8An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7....
CVE-2023-40723HIGH8.1An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6....
CVE-2023-37933MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiA...
CVE-2023-52971MEDIUM4.9MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
CVE-2023-52970MEDIUM4.9MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11....
CVE-2023-52969MEDIUM4.9MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes cra...
CVE-2023-52968MEDIUM4.9MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 be...
CVE-2023-43052MEDIUM5.3IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper valid...
CVE-2023-35894MEDIUM6.1IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2023-38693CRITICAL9.8Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application devel...
CVE-2023-49031MEDIUM5.1Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a re...
CVE-2023-25574CRITICAL9.8`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticato...
CVE-2023-52926HIGH7.8In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provid...
CVE-2023-4261Rejected reason: This CVE ID is Rejected because the issue was not a vulnerability. The data field reported is not attac...
CVE-2023-51339MEDIUM6.5A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to s...
CVE-2023-51338MEDIUM5.4PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, n...
CVE-2023-51337MEDIUM5.4PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index...
CVE-2023-51336HIGH8.8PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to exe...
CVE-2023-51335MEDIUM6.5PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" p...
CVE-2023-51334MEDIUM5.3A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to se...
CVE-2023-51333HIGH8.8PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute r...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now