2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33975 | CRITICAL | 9.8 | 1.5% | May 30, 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process ... |
| CVE-2023-2972 | CRITICAL | 9.8 | 1.0% | May 30, 2023 | Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. |
| CVE-2023-33193 | CRITICAL | 9.1 | 1.7% | May 30, 2023 | Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any for... |
| CVE-2023-33189 | CRITICAL | 9.8 | 0.9% | May 30, 2023 | Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio... |
| CVE-2023-34205 | CRITICAL | 9.1 | 0.4% | May 30, 2023 | In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon... |
| CVE-2023-32692 | CRITICAL | 9.8 | 1.1% | May 30, 2023 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us... |
| CVE-2023-2962 | CRITICAL | 9.8 | 0.7% | May 29, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affec... |
| CVE-2023-2955 | CRITICAL | 9.8 | 0.8% | May 29, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet Syst... |
| CVE-2023-2951 | CRITICAL | 9.1 | 0.8% | May 28, 2023 | A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected... |
| CVE-2023-2927 | CRITICAL | 9.8 | 0.9% | May 27, 2023 | A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the f... |
| CVE-2023-2924 | CRITICAL | 9.8 | 24.3% | May 27, 2023 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this ... |
| CVE-2023-2923 | CRITICAL | 9.8 | 1.0% | May 27, 2023 | A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability ... |
| CVE-2023-32321 | CRITICAL | 9.8 | 1.7% | May 26, 2023 | CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee... |
| CVE-2023-21516 | CRITICAL | 9.6 | 0.5% | May 26, 2023 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API ... |
| CVE-2023-30145 | CRITICAL | 9.8 | 46.1% | May 26, 2023 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para... |
| CVE-2023-32074 | CRITICAL | 9.8 | 0.9% | May 25, 2023 | user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. I... |
| CVE-2023-33280 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be execut... |
| CVE-2023-33279 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed w... |
| CVE-2023-33278 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a... |
| CVE-2023-2851 | CRITICAL | 9.8 | 0.7% | May 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron... |
| CVE-2023-2887 | CRITICAL | 9.8 | 0.8% | May 25, 2023 | Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbo... |
| CVE-2023-2884 | CRITICAL | 9.8 | 0.7% | May 25, 2023 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability i... |
| CVE-2023-2882 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This... |
| CVE-2023-2734 | CRITICAL | 9.8 | 3.8% | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This... |
| CVE-2023-2733 | CRITICAL | 9.8 | 1.3% | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now