2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20214 | CRITICAL | 9.1 | 0.7% | Aug 3, 2023 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a... |
| CVE-2023-33666 | CRITICAL | 9.8 | 0.5% | Aug 3, 2023 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /... |
| CVE-2023-38942 | CRITICAL | 9.8 | 1.6% | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/c... |
| CVE-2023-36217 | CRITICAL | 9 | 1.4% | Aug 3, 2023 | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the cate... |
| CVE-2023-36213 | CRITICAL | 9.8 | 1.1% | Aug 3, 2023 | SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of ... |
| CVE-2023-4121 | CRITICAL | 9.8 | 2.3% | Aug 3, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. A... |
| CVE-2023-4120 | CRITICAL | 9.8 | 81.1% | Aug 3, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue... |
| CVE-2023-4008 | CRITICAL | 9.8 | 0.6% | Aug 3, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions start... |
| CVE-2023-21409 | CRITICAL | 9.8 | 0.6% | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials all... |
| CVE-2023-21408 | CRITICAL | 9.8 | 0.6% | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are use... |
| CVE-2023-3346 | CRITICAL | 9.8 | 1.7% | Aug 3, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a re... |
| CVE-2023-37679 | CRITICAL | 9.8 | 97.1% | Aug 3, 2023 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com... |
| CVE-2023-37364 | CRITICAL | 9.1 | 0.5% | Aug 3, 2023 | In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows... |
| CVE-2023-38954 | CRITICAL | 9.8 | 0.5% | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-36082 | CRITICAL | 9.8 | 1.0% | Aug 3, 2023 | An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP an... |
| CVE-2023-33371 | CRITICAL | 9.8 | 0.9% | Aug 3, 2023 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens... |
| CVE-2023-33369 | CRITICAL | 9.1 | 0.7% | Aug 3, 2023 | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary ... |
| CVE-2023-1935 | CRITICAL | 9.4 | 0.5% | Aug 2, 2023 | ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized... |
| CVE-2023-1437 | CRITICAL | 9.8 | 2.8% | Aug 2, 2023 | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments ... |
| CVE-2023-26317 | CRITICAL | 9.8 | 0.9% | Aug 2, 2023 | Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filteri... |
| CVE-2023-26443 | CRITICAL | 9.8 | 0.7% | Aug 2, 2023 | Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati... |
| CVE-2023-33562 | CRITICAL | 9.8 | 0.6% | Aug 1, 2023 | User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery... |
| CVE-2023-33561 | CRITICAL | 9.8 | 0.8% | Aug 1, 2023 | Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure pas... |
| CVE-2023-36210 | CRITICAL | 9.8 | 28.6% | Aug 1, 2023 | MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerab... |
| CVE-2023-33493 | CRITICAL | 9.8 | 0.7% | Aug 1, 2023 | An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmana... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now