2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3076 | CRITICAL | 9.8 | 1.7% | Jul 10, 2023 | The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of thei... |
| CVE-2023-3045 | CRITICAL | 9.8 | 0.8% | Jul 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Pa... |
| CVE-2023-37152 | CRITICAL | 9.8 | 1.7% | Jul 10, 2023 | Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the admi... |
| CVE-2023-2852 | CRITICAL | 9.8 | 0.7% | Jul 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron... |
| CVE-2023-2046 | CRITICAL | 9.8 | 0.7% | Jul 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics... |
| CVE-2023-37287 | CRITICAL | 9.1 | 0.7% | Jul 10, 2023 | SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit ... |
| CVE-2023-37286 | CRITICAL | 9.8 | 0.8% | Jul 10, 2023 | SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use t... |
| CVE-2023-37173 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command para... |
| CVE-2023-37172 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter... |
| CVE-2023-37171 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser para... |
| CVE-2023-37170 | CRITICAL | 9.8 | 1.4% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnera... |
| CVE-2023-36994 | CRITICAL | 9.8 | 0.7% | Jul 7, 2023 | In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the ser... |
| CVE-2023-36993 | CRITICAL | 9.8 | 0.8% | Jul 7, 2023 | The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset func... |
| CVE-2023-27845 | CRITICAL | 9.8 | 0.8% | Jul 7, 2023 | SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges ... |
| CVE-2023-37149 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param... |
| CVE-2023-37148 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter... |
| CVE-2023-37146 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param... |
| CVE-2023-37145 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname param... |
| CVE-2023-37144 | CRITICAL | 9.8 | 2.1% | Jul 7, 2023 | Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the functio... |
| CVE-2023-34995 | CRITICAL | 9.8 | 0.5% | Jul 7, 2023 | There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a su... |
| CVE-2023-34433 | CRITICAL | 9.8 | 0.3% | Jul 7, 2023 | PiiGAB M-Bus stores passwords using a weak hash algorithm. |
| CVE-2023-36859 | CRITICAL | 9.8 | 0.6% | Jul 6, 2023 | PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbit... |
| CVE-2023-35987 | CRITICAL | 9.8 | 0.6% | Jul 6, 2023 | PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. |
| CVE-2023-33868 | CRITICAL | 9.8 | 0.5% | Jul 6, 2023 | The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic auth... |
| CVE-2023-29824 | CRITICAL | 9.8 | 1.1% | Jul 6, 2023 | A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now