2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26612 | CRITICAL | 9.8 | 1.1% | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field i... |
| CVE-2023-34849 | CRITICAL | 9.8 | 2.6% | Jun 29, 2023 | An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai route... |
| CVE-2023-34844 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape. |
| CVE-2023-34598 | CRITICAL | 9.8 | 44.9% | Jun 29, 2023 | Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files... |
| CVE-2023-3458 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vul... |
| CVE-2023-3457 | CRITICAL | 9.8 | 0.8% | Jun 29, 2023 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk... |
| CVE-2023-34735 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. |
| CVE-2023-34487 | CRITICAL | 9.8 | 0.7% | Jun 29, 2023 | itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points e... |
| CVE-2023-2982 | CRITICAL | 9.8 | 44.6% | Jun 29, 2023 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe... |
| CVE-2023-34738 | CRITICAL | 9.8 | 0.6% | Jun 29, 2023 | Chemex through 3.7.1 is vulnerable to arbitrary file upload. |
| CVE-2023-36475 | CRITICAL | 9.8 | 2.7% | Jun 28, 2023 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2023-3243 | CRITICAL | 9.8 | 0.5% | Jun 28, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. ... |
| CVE-2023-32224 | CRITICAL | 9.8 | 1.2% | Jun 28, 2023 | D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts |
| CVE-2023-32222 | CRITICAL | 9.8 | 1.5% | Jun 28, 2023 | D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method. |
| CVE-2023-21517 | CRITICAL | 9.8 | 1.6% | Jun 28, 2023 | Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execu... |
| CVE-2023-33592 | CRITICAL | 9.8 | 1.9% | Jun 28, 2023 | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf... |
| CVE-2023-21066 | CRITICAL | 9.8 | 0.5% | Jun 28, 2023 | In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to r... |
| CVE-2023-27866 | CRITICAL | 9.8 | 0.9% | Jun 28, 2023 | IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver cod... |
| CVE-2023-32623 | CRITICAL | 9.1 | 1.2% | Jun 28, 2023 | Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to de... |
| CVE-2023-26134 | CRITICAL | 9.8 | 3.3% | Jun 28, 2023 | Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported ... |
| CVE-2023-34240 | CRITICAL | 9.8 | 0.4% | Jun 27, 2023 | Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target f... |
| CVE-2023-3432 | CRITICAL | 10 | 0.7% | Jun 27, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. |
| CVE-2023-2601 | CRITICAL | 9.8 | 1.8% | Jun 27, 2023 | The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ... |
| CVE-2023-2068 | CRITICAL | 9.8 | 39.6% | Jun 27, 2023 | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disa... |
| CVE-2023-2032 | CRITICAL | 9.8 | 0.7% | Jun 27, 2023 | The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Inj... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now