2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29405 | CRITICAL | 9.8 | 1.7% | Jun 8, 2023 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici... |
| CVE-2023-29404 | CRITICAL | 9.8 | 1.8% | Jun 8, 2023 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici... |
| CVE-2023-29402 | CRITICAL | 9.8 | 1.7% | Jun 8, 2023 | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when ru... |
| CVE-2023-0954 | CRITICAL | 9.8 | 0.7% | Jun 8, 2023 | A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentia... |
| CVE-2023-34566 | CRITICAL | 9.8 | 0.9% | Jun 8, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/sav... |
| CVE-2023-33443 | CRITICAL | 9.8 | 3.5% | Jun 8, 2023 | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attacke... |
| CVE-2023-2986 | CRITICAL | 9.8 | 42.8% | Jun 8, 2023 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a... |
| CVE-2023-23482 | CRITICAL | 9.6 | 0.6% | Jun 8, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action ... |
| CVE-2023-34239 | CRITICAL | 9.1 | 0.7% | Jun 8, 2023 | Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f... |
| CVE-2023-27881 | CRITICAL | 9.9 | 0.7% | Jun 7, 2023 | A user could use the “Upload Resource” functionality to upload files to any location on the disk. |
| CVE-2023-33556 | CRITICAL | 9.8 | 2.0% | Jun 7, 2023 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw para... |
| CVE-2023-33496 | CRITICAL | 9.8 | 1.0% | Jun 7, 2023 | xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net... |
| CVE-2023-31116 | CRITICAL | 9.8 | 0.6% | Jun 7, 2023 | An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permiss... |
| CVE-2023-31114 | CRITICAL | 9.1 | 0.6% | Jun 7, 2023 | An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer ... |
| CVE-2023-34237 | CRITICAL | 9.8 | 1.7% | Jun 7, 2023 | SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remot... |
| CVE-2023-33864 | CRITICAL | 9.8 | 3.6% | Jun 7, 2023 | StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It ... |
| CVE-2023-33863 | CRITICAL | 9.8 | 3.6% | Jun 7, 2023 | SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-... |
| CVE-2023-33282 | CRITICAL | 9.8 | 1.0% | Jun 7, 2023 | Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to lo... |
| CVE-2023-2530 | CRITICAL | 9.8 | 1.1% | Jun 7, 2023 | A privilege escalation allowing remote code execution was discovered in the orchestration service. |
| CVE-2023-33553 | CRITICAL | 9.8 | 1.0% | Jun 7, 2023 | An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges... |
| CVE-2023-20887 | CRITICAL | 9.8 | 98.1% | Jun 7, 2023 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware... |
| CVE-2023-2186 | CRITICAL | 9.8 | 0.7% | Jun 7, 2023 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted... |
| CVE-2023-33604 | CRITICAL | 9.1 | 0.8% | Jun 7, 2023 | Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp... |
| CVE-2023-30400 | CRITICAL | 9.8 | 3.5% | Jun 7, 2023 | An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network ... |
| CVE-2023-34409 | CRITICAL | 9.8 | 1.3% | Jun 6, 2023 | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does no... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now