2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27250CRITICAL9.8Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
CVE-2023-1433HIGH7.2A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problemat...
CVE-2023-1432CRITICAL9.8A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this...
CVE-2023-1431MEDIUM5.3The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and ...
CVE-2023-24671HIGH7.8VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to exe...
CVE-2023-1429MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-24571MEDIUM6.7 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-27095MEDIUM6.5Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddU...
CVE-2023-27084MEDIUM5.3Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information...
CVE-2023-26784CRITICAL9.8SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v...
CVE-2023-24795CRITICAL9.8Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
CVE-2023-24760HIGH8.8An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserContr...
CVE-2023-23150CRITICAL9.8SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.
CVE-2023-28487MEDIUM5.3Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2023-28486MEDIUM5.3Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-26951MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List modul...
CVE-2023-25281HIGH7.5A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a d...
CVE-2023-25280CRITICAL9.8OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr...
CVE-2023-28466HIGH7do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race cond...
CVE-2023-28461CRITICAL9.8Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the ...
CVE-2023-28460HIGH7.2A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted pa...
CVE-2023-28338HIGH7.5Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboun...
CVE-2023-28337HIGH8.8When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be p...
CVE-2023-28099HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_l...
CVE-2023-28098HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially cr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now