2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-30764CRITICAL9.8OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an ar...
CVE-2023-30762CRITICAL9.8Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an...
CVE-2023-29129CRITICAL9.8A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAM...
CVE-2023-27997CRITICAL9.8A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi...
CVE-2023-26204CRITICAL9.8A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi...
CVE-2023-2278CRITICAL9.8The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 ...
CVE-2023-32674CRITICAL9.8Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.
CVE-2023-32673CRITICAL9.8Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are pote...
CVE-2023-26295CRITICAL9.8Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation...
CVE-2023-32220CRITICAL9.8Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
CVE-2023-27716CRITICAL9.8An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privi...
CVE-2023-33626CRITICAL9.8D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi bi...
CVE-2023-33625CRITICAL9.8D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability vi...
CVE-2023-34342CRITICAL9.1AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under ce...
CVE-2023-34335CRITICAL9.1AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl...
CVE-2023-35042CRITICAL9.8GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime(...
CVE-2023-34581CRITICAL9.8Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/...
CVE-2023-26133CRITICAL9.8All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file u...
CVE-2023-35036CRITICAL9.1In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023....
CVE-2023-35034CRITICAL9.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and ...
CVE-2023-22583CRITICAL9.8The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.
CVE-2023-34364CRITICAL9.8A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large v...
CVE-2023-1895CRITICAL9.6The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_conte...
CVE-2023-0291CRITICAL9.1The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the ...
CVE-2023-3173CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now