2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3798 | CRITICAL | 9.8 | 0.8% | Jul 20, 2023 | A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as criti... |
| CVE-2023-3795 | CRITICAL | 9.8 | 0.4% | Jul 20, 2023 | A vulnerability classified as critical was found in Bug Finder ChainCity Real Estate Investment Platform 1.0. Affected b... |
| CVE-2023-3793 | CRITICAL | 9.8 | 0.4% | Jul 20, 2023 | A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing ... |
| CVE-2023-31753 | CRITICAL | 9.8 | 1.1% | Jul 20, 2023 | SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via th... |
| CVE-2023-37165 | CRITICAL | 9.8 | 1.7% | Jul 20, 2023 | Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_po... |
| CVE-2023-3791 | CRITICAL | 9.8 | 0.5% | Jul 20, 2023 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. Affected by this issue is the function actionExpo... |
| CVE-2023-37471 | CRITICAL | 9.8 | 1.0% | Jul 20, 2023 | Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Feder... |
| CVE-2023-38203 | CRITICAL | 9.8 | 97.0% | Jul 20, 2023 | Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deseria... |
| CVE-2023-38408 | CRITICAL | 9.8 | 76.8% | Jul 20, 2023 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot... |
| CVE-2023-37289 | CRITICAL | 9.8 | 0.7% | Jul 20, 2023 | It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in I... |
| CVE-2023-3722 | CRITICAL | 9.8 | 3.3% | Jul 19, 2023 | An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remo... |
| CVE-2023-3519 | CRITICAL | 9.8 | 99.7% | Jul 19, 2023 | Unauthenticated remote code execution |
| CVE-2023-3638 | CRITICAL | 9.8 | 0.6% | Jul 19, 2023 | In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. |
| CVE-2023-34034 | CRITICAL | 9.8 | 3.5% | Jul 19, 2023 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spr... |
| CVE-2023-3463 | CRITICAL | 9.8 | 0.4% | Jul 19, 2023 | All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sour... |
| CVE-2023-3759 | CRITICAL | 9.8 | 0.8% | Jul 19, 2023 | A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. Th... |
| CVE-2023-3765 | CRITICAL | 10 | 70.7% | Jul 19, 2023 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. |
| CVE-2023-3751 | CRITICAL | 9.8 | 0.4% | Jul 19, 2023 | A vulnerability was found in Super Store Finder 3.6. It has been declared as critical. Affected by this vulnerability is... |
| CVE-2023-21975 | CRITICAL | 9 | 0.5% | Jul 18, 2023 | Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account... |
| CVE-2023-21974 | CRITICAL | 9 | 0.5% | Jul 18, 2023 | Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Acc... |
| CVE-2023-36670 | CRITICAL | 9.8 | 1.3% | Jul 18, 2023 | A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute ... |
| CVE-2023-30153 | CRITICAL | 9.8 | 0.8% | Jul 18, 2023 | An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3... |
| CVE-2023-36669 | CRITICAL | 9.8 | 0.7% | Jul 18, 2023 | Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attacke... |
| CVE-2023-35189 | CRITICAL | 9.8 | 0.9% | Jul 18, 2023 | Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an... |
| CVE-2023-38432 | CRITICAL | 9.1 | 2.4% | Jul 18, 2023 | An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relat... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now