2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-3076CRITICAL9.8The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of thei...
CVE-2023-3045CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Pa...
CVE-2023-37152CRITICAL9.8Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the admi...
CVE-2023-2852CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron...
CVE-2023-2046CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics...
CVE-2023-37287CRITICAL9.1SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit ...
CVE-2023-37286CRITICAL9.8SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use t...
CVE-2023-37173CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command para...
CVE-2023-37172CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter...
CVE-2023-37171CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser para...
CVE-2023-37170CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnera...
CVE-2023-36994CRITICAL9.8In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the ser...
CVE-2023-36993CRITICAL9.8The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset func...
CVE-2023-27845CRITICAL9.8SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges ...
CVE-2023-37149CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param...
CVE-2023-37148CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter...
CVE-2023-37146CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param...
CVE-2023-37145CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname param...
CVE-2023-37144CRITICAL9.8Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the functio...
CVE-2023-34995CRITICAL9.8 There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a su...
CVE-2023-34433CRITICAL9.8 PiiGAB M-Bus stores passwords using a weak hash algorithm.
CVE-2023-36859CRITICAL9.8 PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbit...
CVE-2023-35987CRITICAL9.8 PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
CVE-2023-33868CRITICAL9.8 The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic auth...
CVE-2023-29824CRITICAL9.8A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now