2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36097 | CRITICAL | 9.8 | 0.9% | Jun 22, 2023 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. |
| CVE-2023-35926 | CRITICAL | 9.9 | 1.9% | Jun 22, 2023 | Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating ... |
| CVE-2023-35174 | CRITICAL | 9.8 | 1.0% | Jun 22, 2023 | Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to op... |
| CVE-2023-34939 | CRITICAL | 9.8 | 5.0% | Jun 22, 2023 | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the... |
| CVE-2023-29711 | CRITICAL | 9.8 | 70.3% | Jun 22, 2023 | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitr... |
| CVE-2023-20895 | CRITICAL | 9.8 | 1.4% | Jun 22, 2023 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A mal... |
| CVE-2023-20894 | CRITICAL | 9.8 | 33.9% | Jun 22, 2023 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A ... |
| CVE-2023-20893 | CRITICAL | 9.8 | 1.2% | Jun 22, 2023 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malici... |
| CVE-2023-20892 | CRITICAL | 9.8 | 1.8% | Jun 22, 2023 | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation... |
| CVE-2023-34601 | CRITICAL | 9.8 | 0.7% | Jun 22, 2023 | Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable}... |
| CVE-2023-29931 | CRITICAL | 9.8 | 0.9% | Jun 22, 2023 | laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php. |
| CVE-2023-33584 | CRITICAL | 9.8 | 14.2% | Jun 21, 2023 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to ... |
| CVE-2023-34340 | CRITICAL | 9.8 | 1.4% | Jun 21, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:... |
| CVE-2023-34563 | CRITICAL | 9.8 | 13.9% | Jun 20, 2023 | netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. |
| CVE-2023-35885 | CRITICAL | 9.8 | 75.3% | Jun 20, 2023 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. |
| CVE-2023-33869 | CRITICAL | 9.8 | 1.1% | Jun 20, 2023 | Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root ... |
| CVE-2023-3340 | CRITICAL | 9.8 | 0.8% | Jun 20, 2023 | A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this i... |
| CVE-2023-34600 | CRITICAL | 9.8 | 23.7% | Jun 20, 2023 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. |
| CVE-2023-34541 | CRITICAL | 9.8 | 0.9% | Jun 20, 2023 | Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt. |
| CVE-2023-3337 | CRITICAL | 9.8 | 0.7% | Jun 20, 2023 | A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affec... |
| CVE-2023-35854 | CRITICAL | 9.8 | 6.0% | Jun 20, 2023 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain... |
| CVE-2023-3325 | CRITICAL | 9.8 | 0.6% | Jun 20, 2023 | The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique ... |
| CVE-2023-29158 | CRITICAL | 9.1 | 0.6% | Jun 19, 2023 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-o... |
| CVE-2023-34159 | CRITICAL | 9.8 | 0.5% | Jun 19, 2023 | Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to pr... |
| CVE-2023-31411 | CRITICAL | 9.8 | 0.9% | Jun 19, 2023 | A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of AP... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now