2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30945 | CRITICAL | 9.8 | 0.6% | Jun 26, 2023 | Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vul... |
| CVE-2023-32557 | CRITICAL | 9.8 | 1.2% | Jun 26, 2023 | A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated atta... |
| CVE-2023-32521 | CRITICAL | 9.1 | 68.9% | Jun 26, 2023 | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow ... |
| CVE-2023-33404 | CRITICAL | 9.8 | 22.3% | Jun 26, 2023 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net vers... |
| CVE-2023-30261 | CRITICAL | 9.8 | 27.1% | Jun 26, 2023 | Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET ... |
| CVE-2023-36660 | CRITICAL | 9.8 | 0.8% | Jun 25, 2023 | The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. |
| CVE-2023-3197 | CRITICAL | 9.8 | 3.9% | Jun 24, 2023 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi... |
| CVE-2023-35172 | CRITICAL | 9.1 | 0.9% | Jun 23, 2023 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform... |
| CVE-2023-35169 | CRITICAL | 9.8 | 3.2% | Jun 23, 2023 | PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr... |
| CVE-2023-34460 | CRITICAL | 9.8 | 0.6% | Jun 23, 2023 | Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on t... |
| CVE-2023-32419 | CRITICAL | 9.8 | 1.1% | Jun 23, 2023 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.5 and iPadOS 16.5. A remote attacker ... |
| CVE-2023-32412 | CRITICAL | 9.8 | 1.6% | Jun 23, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, mac... |
| CVE-2023-32387 | CRITICAL | 9.8 | 1.7% | Jun 23, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS... |
| CVE-2023-3391 | CRITICAL | 9.8 | 0.7% | Jun 23, 2023 | A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been declared as critical. This... |
| CVE-2023-30258 | CRITICAL | 9.8 | 94.3% | Jun 23, 2023 | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com... |
| CVE-2023-3383 | CRITICAL | 9.8 | 0.8% | Jun 23, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affec... |
| CVE-2023-3380 | CRITICAL | 9.8 | 3.9% | Jun 23, 2023 | A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function... |
| CVE-2023-33299 | CRITICAL | 9.8 | 24.3% | Jun 23, 2023 | A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions ... |
| CVE-2023-3128 | CRITICAL | 9.8 | 4.1% | Jun 22, 2023 | Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a... |
| CVE-2023-28094 | CRITICAL | 9.8 | 0.5% | Jun 22, 2023 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be util... |
| CVE-2023-36355 | CRITICAL | 9.9 | 31.7% | Jun 22, 2023 | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg... |
| CVE-2023-32571 | CRITICAL | 9.8 | 34.9% | Jun 22, 2023 | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted... |
| CVE-2023-2989 | CRITICAL | 9.1 | 1.0% | Jun 22, 2023 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server,... |
| CVE-2023-3326 | CRITICAL | 9.8 | 1.1% | Jun 22, 2023 | pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) fro... |
| CVE-2023-2611 | CRITICAL | 9.8 | 0.7% | Jun 22, 2023 | Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users lis... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now