2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-30945CRITICAL9.8Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vul...
CVE-2023-32557CRITICAL9.8A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated atta...
CVE-2023-32521CRITICAL9.1A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow ...
CVE-2023-33404CRITICAL9.8An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net vers...
CVE-2023-30261CRITICAL9.8Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET ...
CVE-2023-36660CRITICAL9.8The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
CVE-2023-3197CRITICAL9.8The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi...
CVE-2023-35172CRITICAL9.1NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform...
CVE-2023-35169CRITICAL9.8PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr...
CVE-2023-34460CRITICAL9.8Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on t...
CVE-2023-32419CRITICAL9.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.5 and iPadOS 16.5. A remote attacker ...
CVE-2023-32412CRITICAL9.8A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, mac...
CVE-2023-32387CRITICAL9.8A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS...
CVE-2023-3391CRITICAL9.8A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been declared as critical. This...
CVE-2023-30258CRITICAL9.8Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com...
CVE-2023-3383CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affec...
CVE-2023-3380CRITICAL9.8A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function...
CVE-2023-33299CRITICAL9.8A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions ...
CVE-2023-3128CRITICAL9.8Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a...
CVE-2023-28094CRITICAL9.8Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be util...
CVE-2023-36355CRITICAL9.9TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg...
CVE-2023-32571CRITICAL9.8Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted...
CVE-2023-2989CRITICAL9.1Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server,...
CVE-2023-3326CRITICAL9.8pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) fro...
CVE-2023-2611CRITICAL9.8Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users lis...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now