2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-38490CRITICAL10Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6...
CVE-2023-3956CRITICAL9.8The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of ...
CVE-2023-31465CRITICAL9.8An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st...
CVE-2023-33308CRITICAL9.8A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 ...
CVE-2023-26859CRITICAL9.8SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privilege...
CVE-2023-38673CRITICAL9.8PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands o...
CVE-2023-38671CRITICAL9.8Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, informatio...
CVE-2023-38669CRITICAL9.8Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.
CVE-2023-38647CRITICAL9.8An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and th...
CVE-2023-37920CRITICAL9.8Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify...
CVE-2023-37677CRITICAL9.8Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the com...
CVE-2023-37460CRITICAL9.8Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unifie...
CVE-2023-37258CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulne...
CVE-2023-34798CRITICAL9.8An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a...
CVE-2023-35982CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35981CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35980CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2023-35941CRITICAL9.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,...
CVE-2023-37895CRITICAL9.8Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute c...
CVE-2023-3548CRITICAL9.8An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authenti...
CVE-2023-35088CRITICAL9.8Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-35078CRITICAL9.8An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re...
CVE-2023-35066CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software ...
CVE-2023-3046CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ...
CVE-2023-32637CRITICAL9.8GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web reque...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now