2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30764 | CRITICAL | 9.8 | 1.5% | Jun 13, 2023 | OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an ar... |
| CVE-2023-30762 | CRITICAL | 9.8 | 0.7% | Jun 13, 2023 | Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an... |
| CVE-2023-29129 | CRITICAL | 9.8 | 0.9% | Jun 13, 2023 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAM... |
| CVE-2023-27997 | CRITICAL | 9.8 | 85.7% | Jun 13, 2023 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi... |
| CVE-2023-26204 | CRITICAL | 9.8 | 0.4% | Jun 13, 2023 | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi... |
| CVE-2023-2278 | CRITICAL | 9.8 | 1.7% | Jun 13, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 ... |
| CVE-2023-32674 | CRITICAL | 9.8 | 0.9% | Jun 12, 2023 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow. |
| CVE-2023-32673 | CRITICAL | 9.8 | 0.9% | Jun 12, 2023 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are pote... |
| CVE-2023-26295 | CRITICAL | 9.8 | 1.7% | Jun 12, 2023 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation... |
| CVE-2023-32220 | CRITICAL | 9.8 | 0.6% | Jun 12, 2023 | Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. |
| CVE-2023-27716 | CRITICAL | 9.8 | 0.7% | Jun 12, 2023 | An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privi... |
| CVE-2023-33626 | CRITICAL | 9.8 | 1.5% | Jun 12, 2023 | D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi bi... |
| CVE-2023-33625 | CRITICAL | 9.8 | 33.2% | Jun 12, 2023 | D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability vi... |
| CVE-2023-34342 | CRITICAL | 9.1 | 0.5% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under ce... |
| CVE-2023-34335 | CRITICAL | 9.1 | 0.4% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl... |
| CVE-2023-35042 | CRITICAL | 9.8 | 44.8% | Jun 12, 2023 | GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime(... |
| CVE-2023-34581 | CRITICAL | 9.8 | 3.3% | Jun 12, 2023 | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/... |
| CVE-2023-26133 | CRITICAL | 9.8 | 1.3% | Jun 12, 2023 | All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file u... |
| CVE-2023-35036 | CRITICAL | 9.1 | 12.8% | Jun 12, 2023 | In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.... |
| CVE-2023-35034 | CRITICAL | 9.8 | 1.3% | Jun 12, 2023 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and ... |
| CVE-2023-22583 | CRITICAL | 9.8 | 0.8% | Jun 11, 2023 | The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. |
| CVE-2023-34364 | CRITICAL | 9.8 | 1.6% | Jun 9, 2023 | A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large v... |
| CVE-2023-1895 | CRITICAL | 9.6 | 0.6% | Jun 9, 2023 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_conte... |
| CVE-2023-0291 | CRITICAL | 9.1 | 2.0% | Jun 9, 2023 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the ... |
| CVE-2023-3173 | CRITICAL | 9.8 | 1.1% | Jun 9, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now