2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-26612CRITICAL9.8D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field i...
CVE-2023-34849CRITICAL9.8An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai route...
CVE-2023-34844CRITICAL9.8Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.
CVE-2023-34598CRITICAL9.8Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files...
CVE-2023-3458CRITICAL9.8A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vul...
CVE-2023-3457CRITICAL9.8A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk...
CVE-2023-34735CRITICAL9.8Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
CVE-2023-34487CRITICAL9.8itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points e...
CVE-2023-2982CRITICAL9.8The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe...
CVE-2023-34738CRITICAL9.8Chemex through 3.7.1 is vulnerable to arbitrary file upload.
CVE-2023-36475CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2023-3243CRITICAL9.8 ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. ...
CVE-2023-32224CRITICAL9.8D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
CVE-2023-32222CRITICAL9.8D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
CVE-2023-21517CRITICAL9.8Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execu...
CVE-2023-33592CRITICAL9.8Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf...
CVE-2023-21066CRITICAL9.8In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to r...
CVE-2023-27866CRITICAL9.8IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver cod...
CVE-2023-32623CRITICAL9.1Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to de...
CVE-2023-26134CRITICAL9.8Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported ...
CVE-2023-34240CRITICAL9.8Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target f...
CVE-2023-3432CRITICAL10Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
CVE-2023-2601CRITICAL9.8The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ...
CVE-2023-2068CRITICAL9.8The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disa...
CVE-2023-2032CRITICAL9.8The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Inj...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now