2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36258CRITICAL9.8An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex...
CVE-2023-36817CRITICAL9.1`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f...
CVE-2023-26258CRITICAL9.8Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe...
CVE-2023-35797CRITICAL9.8Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A...
CVE-2023-26136CRITICAL9.8Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cook...
CVE-2023-31997CRITICAL9UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to acc...
CVE-2023-28365CRITICAL9.1A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems ...
CVE-2023-28324CRITICAL9.8A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es...
CVE-2023-28323CRITICAL9.8A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to...
CVE-2023-22814CRITICAL9.8An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow ...
CVE-2023-36812CRITICAL9.8OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Exec...
CVE-2023-3490CRITICAL9.8 SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
CVE-2023-31543CRITICAL9.8A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted P...
CVE-2023-37303CRITICAL9.8An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to bl...
CVE-2023-35175CRITICAL9.8Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of...
CVE-2023-3473CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is ...
CVE-2023-2846CRITICAL9.1Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules...
CVE-2023-26135CRITICAL9.8All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest....
CVE-2023-3249CRITICAL9.8The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in version...
CVE-2023-2834CRITICAL9.8The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is ...
CVE-2023-33190CRITICAL9.8Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior...
CVE-2023-36487CRITICAL9.8The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take ov...
CVE-2023-35830CRITICAL9.8STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.0...
CVE-2023-26616CRITICAL9.8D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in Set...
CVE-2023-26613CRITICAL9.8An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now