2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2003 | CRITICAL | 9.8 | 0.9% | Jul 13, 2023 | Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a... |
| CVE-2023-3658 | CRITICAL | 9.8 | 0.5% | Jul 13, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affect... |
| CVE-2023-25178 | CRITICAL | 9.8 | 0.4% | Jul 13, 2023 | Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notifi... |
| CVE-2023-3657 | CRITICAL | 9.8 | 0.5% | Jul 13, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. T... |
| CVE-2023-2957 | CRITICAL | 9.8 | 0.5% | Jul 13, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Flor... |
| CVE-2023-1547 | CRITICAL | 9.8 | 0.6% | Jul 13, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik all... |
| CVE-2023-3342 | CRITICAL | 9.9 | 1.5% | Jul 13, 2023 | The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and... |
| CVE-2023-38199 | CRITICAL | 9.8 | 0.6% | Jul 13, 2023 | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on... |
| CVE-2023-38198 | CRITICAL | 9.8 | 0.9% | Jul 13, 2023 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023. |
| CVE-2023-34137 | CRITICAL | 9.8 | 0.9% | Jul 13, 2023 | SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks lead... |
| CVE-2023-34136 | CRITICAL | 9.8 | 0.7% | Jul 13, 2023 | Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location no... |
| CVE-2023-34132 | CRITICAL | 9.8 | 6.5% | Jul 13, 2023 | Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the... |
| CVE-2023-37567 | CRITICAL | 9.8 | 1.8% | Jul 13, 2023 | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to e... |
| CVE-2023-34130 | CRITICAL | 9.8 | 0.3% | Jul 13, 2023 | SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data.... |
| CVE-2023-34128 | CRITICAL | 9.8 | 0.6% | Jul 13, 2023 | Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: ... |
| CVE-2023-34124 | CRITICAL | 9.8 | 40.9% | Jul 13, 2023 | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio... |
| CVE-2023-21250 | CRITICAL | 9.8 | 0.5% | Jul 13, 2023 | In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2023-20918 | CRITICAL | 9.8 | 0.8% | Jul 13, 2023 | In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused dep... |
| CVE-2023-33274 | CRITICAL | 9.8 | 0.9% | Jul 12, 2023 | The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users ... |
| CVE-2023-26564 | CRITICAL | 9.8 | 1.4% | Jul 12, 2023 | The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As... |
| CVE-2023-26563 | CRITICAL | 9.8 | 1.5% | Jul 12, 2023 | The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an... |
| CVE-2023-3644 | CRITICAL | 9.8 | 0.4% | Jul 12, 2023 | A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. Th... |
| CVE-2023-3643 | CRITICAL | 9.8 | 75.2% | Jul 12, 2023 | A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown par... |
| CVE-2023-37629 | CRITICAL | 9.8 | 15.0% | Jul 12, 2023 | Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send... |
| CVE-2023-37628 | CRITICAL | 9.8 | 0.8% | Jul 12, 2023 | Online Piggery Management System 1.0 is vulnerable to SQL Injection. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now