2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-29405CRITICAL9.8The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici...
CVE-2023-29404CRITICAL9.8The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici...
CVE-2023-29402CRITICAL9.8The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when ru...
CVE-2023-0954CRITICAL9.8A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentia...
CVE-2023-34566CRITICAL9.8Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/sav...
CVE-2023-33443CRITICAL9.8Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attacke...
CVE-2023-2986CRITICAL9.8The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a...
CVE-2023-23482CRITICAL9.6IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action ...
CVE-2023-34239CRITICAL9.1Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f...
CVE-2023-27881CRITICAL9.9 A user could use the “Upload Resource” functionality to upload files to any location on the disk.
CVE-2023-33556CRITICAL9.8TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw para...
CVE-2023-33496CRITICAL9.8xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net...
CVE-2023-31116CRITICAL9.8An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permiss...
CVE-2023-31114CRITICAL9.1An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer ...
CVE-2023-34237CRITICAL9.8SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remot...
CVE-2023-33864CRITICAL9.8StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It ...
CVE-2023-33863CRITICAL9.8SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-...
CVE-2023-33282CRITICAL9.8Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to lo...
CVE-2023-2530CRITICAL9.8A privilege escalation allowing remote code execution was discovered in the orchestration service.
CVE-2023-33553CRITICAL9.8An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges...
CVE-2023-20887CRITICAL9.8Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware...
CVE-2023-2186CRITICAL9.8On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted...
CVE-2023-33604CRITICAL9.1Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp...
CVE-2023-30400CRITICAL9.8An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network ...
CVE-2023-34409CRITICAL9.8In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does no...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now