2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-4058CRITICAL9.8Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-4057CRITICAL9.8Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence ...
CVE-2023-4056CRITICAL9.8Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102...
CVE-2023-31710CRITICAL9.8TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow...
CVE-2023-37478CRITICAL9.8pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry ...
CVE-2023-34960CRITICAL9.8A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex...
CVE-2023-39122CRITICAL9.8BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This i...
CVE-2023-37771CRITICAL9.8Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
CVE-2023-36092CRITICAL9.8Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via ...
CVE-2023-36091CRITICAL9.8Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via ...
CVE-2023-36090CRITICAL9.8Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via...
CVE-2023-36089CRITICAL9.8Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated pr...
CVE-2023-34842CRITICAL9.8Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted...
CVE-2023-34644CRITICAL9.8Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204...
CVE-2023-34635CRITICAL9.8Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not vali...
CVE-2023-37647CRITICAL9.8SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
CVE-2023-35861CRITICAL9.8A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) all...
CVE-2023-4006CRITICAL9.8Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
CVE-2023-4005CRITICAL9.8Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
CVE-2023-37215CRITICAL9.8 JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
CVE-2023-37214CRITICAL9.8 Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
CVE-2023-37213CRITICAL9.8 Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
CVE-2023-32227CRITICAL9.8 Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
CVE-2023-39023CRITICAL9.8university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compas...
CVE-2023-39022CRITICAL9.8oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now