2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36460CRITICAL9.9Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versi...
CVE-2023-3528CRITICAL9.8A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unkno...
CVE-2023-34192CRITICAL9Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co...
CVE-2023-30321CRITICAL9Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine...
CVE-2023-30320CRITICAL9Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine c...
CVE-2023-30319CRITICAL9.6Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine co...
CVE-2023-29382CRITICAL9.8An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preaut...
CVE-2023-29381CRITICAL9.8An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sen...
CVE-2023-23902CRITICAL9.8A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially craft...
CVE-2023-22844CRITICAL9.8An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0....
CVE-2023-22319CRITICAL9.8A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specia...
CVE-2023-36188CRITICAL9.8An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Pyth...
CVE-2023-37245CRITICAL9.1Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the ...
CVE-2023-37242CRITICAL9.8Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnera...
CVE-2023-37240CRITICAL9.1 Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vul...
CVE-2023-36808CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer ...
CVE-2023-35924CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI in...
CVE-2023-34338CRITICAL9.8AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-...
CVE-2023-36934CRITICAL9.1In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1....
CVE-2023-36665CRITICAL9.8"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than...
CVE-2023-3455CRITICAL9.1Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability an...
CVE-2023-3504CRITICAL9.8A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some ...
CVE-2023-3460CRITICAL9.8The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary c...
CVE-2023-21631CRITICAL9.8Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received...
CVE-2023-30990CRITICAL9.8IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now