2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2907 | CRITICAL | 9.8 | 0.6% | Jun 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQ... |
| CVE-2023-27992 | CRITICAL | 9.8 | 84.3% | Jun 19, 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, ... |
| CVE-2023-34417 | CRITICAL | 9.8 | 0.8% | Jun 19, 2023 | Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2023-34416 | CRITICAL | 9.8 | 0.9% | Jun 19, 2023 | Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidenc... |
| CVE-2023-29542 | CRITICAL | 9.8 | 0.9% | Jun 19, 2023 | A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious fil... |
| CVE-2023-29534 | CRITICAL | 9.1 | 0.7% | Jun 19, 2023 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have ... |
| CVE-2023-25736 | CRITICAL | 9.8 | 0.7% | Jun 19, 2023 | An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affe... |
| CVE-2023-32216 | CRITICAL | 9.8 | 0.8% | Jun 19, 2023 | Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team repo... |
| CVE-2023-29531 | CRITICAL | 9.8 | 1.0% | Jun 19, 2023 | An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potent... |
| CVE-2023-27396 | CRITICAL | 9.8 | 1.4% | Jun 19, 2023 | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA ... |
| CVE-2023-35857 | CRITICAL | 9.8 | 0.6% | Jun 19, 2023 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. |
| CVE-2023-35856 | CRITICAL | 9.8 | 1.1% | Jun 19, 2023 | A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to exe... |
| CVE-2023-35855 | CRITICAL | 9.8 | 1.1% | Jun 19, 2023 | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's mac... |
| CVE-2023-35853 | CRITICAL | 9.8 | 1.0% | Jun 19, 2023 | In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. Th... |
| CVE-2023-35839 | CRITICAL | 9.8 | 1.1% | Jun 19, 2023 | A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing c... |
| CVE-2023-3306 | CRITICAL | 9.8 | 23.1% | Jun 18, 2023 | A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability af... |
| CVE-2023-35813 | CRITICAL | 9.8 | 86.7% | Jun 17, 2023 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi... |
| CVE-2023-35784 | CRITICAL | 9.8 | 0.9% | Jun 16, 2023 | A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, ... |
| CVE-2023-34832 | CRITICAL | 9.8 | 1.7% | Jun 16, 2023 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. |
| CVE-2023-34659 | CRITICAL | 9.8 | 12.5% | Jun 16, 2023 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interfac... |
| CVE-2023-25366 | CRITICAL | 9.8 | 0.4% | Jun 16, 2023 | In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password. |
| CVE-2023-35782 | CRITICAL | 9.8 | 0.5% | Jun 16, 2023 | The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection. |
| CVE-2023-34548 | CRITICAL | 9.8 | 0.9% | Jun 16, 2023 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. |
| CVE-2023-35708 | CRITICAL | 9.8 | 92.1% | Jun 16, 2023 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.... |
| CVE-2023-32754 | CRITICAL | 9.8 | 1.0% | Jun 16, 2023 | Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now