2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39107 | CRITICAL | 9.1 | 1.0% | Aug 4, 2023 | An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows... |
| CVE-2023-38692 | CRITICAL | 9.8 | 2.8% | Aug 4, 2023 | CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command i... |
| CVE-2023-33379 | CRITICAL | 9.8 | 0.7% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, ... |
| CVE-2023-33378 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro... |
| CVE-2023-33377 | CRITICAL | 9.8 | 1.5% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its commu... |
| CVE-2023-33376 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati... |
| CVE-2023-33375 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling at... |
| CVE-2023-33374 | CRITICAL | 9.8 | 1.3% | Aug 4, 2023 | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to sp... |
| CVE-2023-33373 | CRITICAL | 9.8 | 0.4% | Aug 4, 2023 | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the... |
| CVE-2023-33372 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi... |
| CVE-2023-39143 | CRITICAL | 9.8 | 78.7% | Aug 4, 2023 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete... |
| CVE-2023-38690 | CRITICAL | 9.8 | 0.8% | Aug 4, 2023 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with... |
| CVE-2023-38689 | CRITICAL | 9.8 | 1.2% | Aug 4, 2023 | Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `Object... |
| CVE-2023-37470 | CRITICAL | 9.8 | 1.1% | Aug 4, 2023 | Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,... |
| CVE-2023-36480 | CRITICAL | 9.8 | 1.7% | Aug 4, 2023 | The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike serv... |
| CVE-2023-29689 | CRITICAL | 9.8 | 41.1% | Aug 4, 2023 | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in... |
| CVE-2023-3373 | CRITICAL | 9.1 | 0.8% | Aug 4, 2023 | Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model ... |
| CVE-2023-38941 | CRITICAL | 9.8 | 1.3% | Aug 4, 2023 | django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspa... |
| CVE-2023-36139 | CRITICAL | 9.8 | 0.3% | Aug 4, 2023 | In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on th... |
| CVE-2023-36134 | CRITICAL | 9.8 | 0.4% | Aug 4, 2023 | In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the ... |
| CVE-2023-36133 | CRITICAL | 9.8 | 0.7% | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. |
| CVE-2023-36132 | CRITICAL | 9.8 | 0.7% | Aug 4, 2023 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. |
| CVE-2023-36131 | CRITICAL | 9.8 | 0.7% | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation ... |
| CVE-2023-33665 | CRITICAL | 9.8 | 0.5% | Aug 4, 2023 | ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.ph... |
| CVE-2023-38951 | CRITICAL | 9.8 | 3.2% | Aug 3, 2023 | ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arb... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now