2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-39107CRITICAL9.1An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows...
CVE-2023-38692CRITICAL9.8CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command i...
CVE-2023-33379CRITICAL9.8Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, ...
CVE-2023-33378CRITICAL9.8Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro...
CVE-2023-33377CRITICAL9.8Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its commu...
CVE-2023-33376CRITICAL9.8Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati...
CVE-2023-33375CRITICAL9.8Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling at...
CVE-2023-33374CRITICAL9.8Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to sp...
CVE-2023-33373CRITICAL9.8Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the...
CVE-2023-33372CRITICAL9.8Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi...
CVE-2023-39143CRITICAL9.8PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete...
CVE-2023-38690CRITICAL9.8matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with...
CVE-2023-38689CRITICAL9.8Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `Object...
CVE-2023-37470CRITICAL9.8Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,...
CVE-2023-36480CRITICAL9.8The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike serv...
CVE-2023-29689CRITICAL9.8PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in...
CVE-2023-3373CRITICAL9.1Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model ...
CVE-2023-38941CRITICAL9.8django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspa...
CVE-2023-36139CRITICAL9.8In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on th...
CVE-2023-36134CRITICAL9.8In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the ...
CVE-2023-36133CRITICAL9.8PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
CVE-2023-36132CRITICAL9.8PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
CVE-2023-36131CRITICAL9.8PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation ...
CVE-2023-33665CRITICAL9.8ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.ph...
CVE-2023-38951CRITICAL9.8ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arb...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now