2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-29632CRITICAL9.8PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
CVE-2023-34111CRITICAL9.8The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerabili...
CVE-2023-33532CRITICAL9.8There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker ga...
CVE-2023-31569CRITICAL9.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
CVE-2023-32628CRITICAL9.8 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an a...
CVE-2023-32540CRITICAL9.8 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an ...
CVE-2023-29631CRITICAL9.8PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
CVE-2023-29630CRITICAL9.8PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.
CVE-2023-29629CRITICAL9.8PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.
CVE-2023-33386CRITICAL9.8MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
CVE-2023-3065CRITICAL9.1Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue af...
CVE-2023-3100CRITICAL9.8A vulnerability, which was classified as critical, has been found in IBOS 4.5.5. Affected by this issue is the function ...
CVE-2023-0636CRITICAL9.8Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2C...
CVE-2023-0635CRITICAL9.8Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021...
CVE-2023-3094CRITICAL9.8A vulnerability classified as critical has been found in code-projects Agro-School Management System 1.0. Affected is th...
CVE-2023-3086CRITICAL9Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-2781CRITICAL9.8The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate...
CVE-2023-33762CRITICAL9.8eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity...
CVE-2023-33675CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_li...
CVE-2023-33673CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal...
CVE-2023-33671CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentContro...
CVE-2023-33670CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.
CVE-2023-33669CRITICAL9.8Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct...
CVE-2023-3069CRITICAL9.8Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-3068CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unkn...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now