2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37027MEDIUM6.5Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 084...
CVE-2023-37026MEDIUM6.5A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0...
CVE-2023-37025MEDIUM6.5A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0...
CVE-2023-37024HIGH7.5A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8...
CVE-2023-50733HIGH8.6A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devi...
CVE-2023-27113CRITICAL9.8pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at pro...
CVE-2023-27112CRITICAL9.8pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project....
CVE-2023-45908MEDIUM6.1Homarr before v0.14.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notebook widge...
CVE-2023-52923MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: adapt set backend to use GC t...
CVE-2023-50739HIGH8.8A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. ...
CVE-2023-50738MEDIUM4.3A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this dow...
CVE-2023-22139Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is mistakenly publ...
CVE-2023-4319Rejected reason: This CVE ID is a reservation duplicate of CVE-2023-4677. Notes: All CVE users should reference CVE-2023...
CVE-2023-46715MEDIUM4.3An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and versio...
CVE-2023-42786MEDIUM6.5A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versi...
CVE-2023-42785MEDIUM6.5A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versi...
CVE-2023-37937HIGH7.8An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch ve...
CVE-2023-37936CRITICAL9.8A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7....
CVE-2023-37931HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiV...
CVE-2023-42250MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.
CVE-2023-42249MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.
CVE-2023-42248MEDIUM6.5An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbi...
CVE-2023-42247MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.
CVE-2023-42246MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.
CVE-2023-42245MEDIUM6.1Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now