2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36097CRITICAL9.8funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
CVE-2023-35926CRITICAL9.9Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating ...
CVE-2023-35174CRITICAL9.8Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to op...
CVE-2023-34939CRITICAL9.8Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the...
CVE-2023-29711CRITICAL9.8An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitr...
CVE-2023-20895CRITICAL9.8The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A mal...
CVE-2023-20894CRITICAL9.8The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A ...
CVE-2023-20893CRITICAL9.8The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malici...
CVE-2023-20892CRITICAL9.8The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation...
CVE-2023-34601CRITICAL9.8Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable}...
CVE-2023-29931CRITICAL9.8laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
CVE-2023-33584CRITICAL9.8Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to ...
CVE-2023-34340CRITICAL9.8Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:...
CVE-2023-34563CRITICAL9.8netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
CVE-2023-35885CRITICAL9.8CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CVE-2023-33869CRITICAL9.8 Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root ...
CVE-2023-3340CRITICAL9.8A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this i...
CVE-2023-34600CRITICAL9.8Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
CVE-2023-34541CRITICAL9.8Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
CVE-2023-3337CRITICAL9.8A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affec...
CVE-2023-35854CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain...
CVE-2023-3325CRITICAL9.8The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique ...
CVE-2023-29158CRITICAL9.1 SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-o...
CVE-2023-34159CRITICAL9.8Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to pr...
CVE-2023-31411CRITICAL9.8A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of AP...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now