2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-2003CRITICAL9.8Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a...
CVE-2023-3658CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affect...
CVE-2023-25178CRITICAL9.8Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notifi...
CVE-2023-3657CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. T...
CVE-2023-2957CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Flor...
CVE-2023-1547CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik all...
CVE-2023-3342CRITICAL9.9The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and...
CVE-2023-38199CRITICAL9.8coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on...
CVE-2023-38198CRITICAL9.8acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
CVE-2023-34137CRITICAL9.8SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks lead...
CVE-2023-34136CRITICAL9.8Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location no...
CVE-2023-34132CRITICAL9.8Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the...
CVE-2023-37567CRITICAL9.8Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to e...
CVE-2023-34130CRITICAL9.8SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data....
CVE-2023-34128CRITICAL9.8Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: ...
CVE-2023-34124CRITICAL9.8The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio...
CVE-2023-21250CRITICAL9.8In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2023-20918CRITICAL9.8In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused dep...
CVE-2023-33274CRITICAL9.8The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users ...
CVE-2023-26564CRITICAL9.8The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As...
CVE-2023-26563CRITICAL9.8The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an...
CVE-2023-3644CRITICAL9.8A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. Th...
CVE-2023-3643CRITICAL9.8A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown par...
CVE-2023-37629CRITICAL9.8Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send...
CVE-2023-37628CRITICAL9.8Online Piggery Management System 1.0 is vulnerable to SQL Injection.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now