2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4058 | CRITICAL | 9.8 | 0.6% | Aug 1, 2023 | Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2023-4057 | CRITICAL | 9.8 | 0.7% | Aug 1, 2023 | Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence ... |
| CVE-2023-4056 | CRITICAL | 9.8 | 0.8% | Aug 1, 2023 | Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102... |
| CVE-2023-31710 | CRITICAL | 9.8 | 0.6% | Aug 1, 2023 | TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow... |
| CVE-2023-37478 | CRITICAL | 9.8 | 0.9% | Aug 1, 2023 | pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry ... |
| CVE-2023-34960 | CRITICAL | 9.8 | 99.4% | Aug 1, 2023 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex... |
| CVE-2023-39122 | CRITICAL | 9.8 | 0.6% | Jul 31, 2023 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This i... |
| CVE-2023-37771 | CRITICAL | 9.8 | 1.3% | Jul 31, 2023 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. |
| CVE-2023-36092 | CRITICAL | 9.8 | 1.1% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via ... |
| CVE-2023-36091 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via ... |
| CVE-2023-36090 | CRITICAL | 9.8 | 1.1% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via... |
| CVE-2023-36089 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated pr... |
| CVE-2023-34842 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted... |
| CVE-2023-34644 | CRITICAL | 9.8 | 1.5% | Jul 31, 2023 | Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204... |
| CVE-2023-34635 | CRITICAL | 9.8 | 2.1% | Jul 31, 2023 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not vali... |
| CVE-2023-37647 | CRITICAL | 9.8 | 0.6% | Jul 31, 2023 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. |
| CVE-2023-35861 | CRITICAL | 9.8 | 1.5% | Jul 31, 2023 | A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) all... |
| CVE-2023-4006 | CRITICAL | 9.8 | 0.7% | Jul 31, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16. |
| CVE-2023-4005 | CRITICAL | 9.8 | 0.4% | Jul 31, 2023 | Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. |
| CVE-2023-37215 | CRITICAL | 9.8 | 0.4% | Jul 30, 2023 | JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials |
| CVE-2023-37214 | CRITICAL | 9.8 | 0.6% | Jul 30, 2023 | Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. |
| CVE-2023-37213 | CRITICAL | 9.8 | 1.1% | Jul 30, 2023 | Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection' |
| CVE-2023-32227 | CRITICAL | 9.8 | 0.5% | Jul 30, 2023 | Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials |
| CVE-2023-39023 | CRITICAL | 9.8 | 0.8% | Jul 28, 2023 | university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compas... |
| CVE-2023-39022 | CRITICAL | 9.8 | 1.0% | Jul 28, 2023 | oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now