CVE Vulnerabilities in 2023

198 documented vulnerabilities published in 2023.

Other years: 2026 2025 2024 2022 2021 2020

Top Affected Vendors in 2023

All CVEs from 2023

CVE-2022-4554
5.4 medium

B2B Customer Ordering System developed by ID Software Project and Consultancy Services before version 1.0.0.347 has an authenticated Reflected XSS vulnerability. This has been fixed in the version 1.0.0.347.

Idyazilim B2B Dealer Order System Jan 24, 2023
CVE-2021-36647
4.7 medium

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking

Arm Mbed Tls Jan 17, 2023
CVE-2022-47630
7.4 high

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

Trustedfirmware Trusted Firmware-A Jan 16, 2023
CVE-2022-3693
7.5 high

Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3.

Fileorbis Fileorbis Jan 13, 2023
CVE-2022-4422
9.8 critical

Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injection vulnerability. This has been fixed in the version 3.0

Bulutses Bulutdesk Callcenter Jan 10, 2023
CVE-2022-3792
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.

Gullseye Gullseye Terminal Operating System Jan 10, 2023