2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3359MEDIUM5.5An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the r...
CVE-2023-3358MEDIUM5.5A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a ...
CVE-2023-3357MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local use...
CVE-2023-36474MEDIUM6.1Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prio...
CVE-2023-34736HIGH7.2Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
CVE-2023-34647MEDIUM6.1PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-3439MEDIUM4.7A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant...
CVE-2023-3390HIGH7.8A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mi...
CVE-2023-3355MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c code in the submit_...
CVE-2023-3243CRITICAL9.8 ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. ...
CVE-2023-3138HIGH7.5A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not ch...
CVE-2023-34652MEDIUM6.1PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
CVE-2023-34651MEDIUM6.1PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34650MEDIUM6.1PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-32224CRITICAL9.8D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
CVE-2023-32223HIGH8.8D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.
CVE-2023-32222CRITICAL9.8D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
CVE-2023-2232MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulner...
CVE-2023-21518HIGH7.8Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications...
CVE-2023-21517CRITICAL9.8Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execu...
CVE-2023-21513MEDIUM6.8Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to mani...
CVE-2023-21512LOW3.3Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to re...
CVE-2023-3389HIGH7.8A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escala...
CVE-2023-3090HIGH7.8A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local pri...
CVE-2023-34761MEDIUM6.5An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now