2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27250 | CRITICAL | 9.8 | 0.8% | Mar 16, 2023 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. |
| CVE-2023-1433 | HIGH | 7.2 | 0.9% | Mar 16, 2023 | A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problemat... |
| CVE-2023-1432 | CRITICAL | 9.8 | 0.6% | Mar 16, 2023 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this... |
| CVE-2023-1431 | MEDIUM | 5.3 | 0.5% | Mar 16, 2023 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and ... |
| CVE-2023-24671 | HIGH | 7.8 | 0.4% | Mar 16, 2023 | VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to exe... |
| CVE-2023-1429 | MEDIUM | 5.4 | 0.4% | Mar 16, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19. |
| CVE-2023-24571 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator ... |
| CVE-2023-27095 | MEDIUM | 6.5 | 0.6% | Mar 16, 2023 | Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddU... |
| CVE-2023-27084 | MEDIUM | 5.3 | 0.2% | Mar 16, 2023 | Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information... |
| CVE-2023-26784 | CRITICAL | 9.8 | 0.7% | Mar 16, 2023 | SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v... |
| CVE-2023-24795 | CRITICAL | 9.8 | 1.0% | Mar 16, 2023 | Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483. |
| CVE-2023-24760 | HIGH | 8.8 | 0.8% | Mar 16, 2023 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserContr... |
| CVE-2023-23150 | CRITICAL | 9.8 | 0.8% | Mar 16, 2023 | SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution. |
| CVE-2023-28487 | MEDIUM | 5.3 | 1.0% | Mar 16, 2023 | Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
| CVE-2023-28486 | MEDIUM | 5.3 | 0.9% | Mar 16, 2023 | Sudo before 1.9.13 does not escape control characters in log messages. |
| CVE-2023-26951 | MEDIUM | 5.4 | 0.3% | Mar 16, 2023 | onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List modul... |
| CVE-2023-25281 | HIGH | 7.5 | 1.1% | Mar 16, 2023 | A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a d... |
| CVE-2023-25280 | CRITICAL | 9.8 | 98.1% | Mar 16, 2023 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr... |
| CVE-2023-28466 | HIGH | 7 | 0.3% | Mar 16, 2023 | do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race cond... |
| CVE-2023-28461 | CRITICAL | 9.8 | 67.9% | Mar 15, 2023 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the ... |
| CVE-2023-28460 | HIGH | 7.2 | 1.6% | Mar 15, 2023 | A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted pa... |
| CVE-2023-28338 | HIGH | 7.5 | 0.6% | Mar 15, 2023 | Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboun... |
| CVE-2023-28337 | HIGH | 8.8 | 0.7% | Mar 15, 2023 | When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be p... |
| CVE-2023-28099 | HIGH | 7.5 | 0.9% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_l... |
| CVE-2023-28098 | HIGH | 7.5 | 0.9% | Mar 15, 2023 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially cr... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now