2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-20214CRITICAL9.1A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a...
CVE-2023-33666CRITICAL9.8ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /...
CVE-2023-38942CRITICAL9.8Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/c...
CVE-2023-36217CRITICAL9Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the cate...
CVE-2023-36213CRITICAL9.8SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of ...
CVE-2023-4121CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. A...
CVE-2023-4120CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue...
CVE-2023-4008CRITICAL9.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions start...
CVE-2023-21409CRITICAL9.8 Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials all...
CVE-2023-21408CRITICAL9.8 Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are use...
CVE-2023-3346CRITICAL9.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a re...
CVE-2023-37679CRITICAL9.8A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com...
CVE-2023-37364CRITICAL9.1In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows...
CVE-2023-38954CRITICAL9.8ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
CVE-2023-36082CRITICAL9.8An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP an...
CVE-2023-33371CRITICAL9.8Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens...
CVE-2023-33369CRITICAL9.1A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary ...
CVE-2023-1935CRITICAL9.4ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized...
CVE-2023-1437CRITICAL9.8All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments ...
CVE-2023-26317CRITICAL9.8Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filteri...
CVE-2023-26443CRITICAL9.8Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati...
CVE-2023-33562CRITICAL9.8User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery...
CVE-2023-33561CRITICAL9.8Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure pas...
CVE-2023-36210CRITICAL9.8MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerab...
CVE-2023-33493CRITICAL9.8An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmana...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now