2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-33975CRITICAL9.8RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process ...
CVE-2023-2972CRITICAL9.8Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
CVE-2023-33193CRITICAL9.1Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any for...
CVE-2023-33189CRITICAL9.8Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio...
CVE-2023-34205CRITICAL9.1In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon...
CVE-2023-32692CRITICAL9.8CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us...
CVE-2023-2962CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affec...
CVE-2023-2955CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet Syst...
CVE-2023-2951CRITICAL9.1A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected...
CVE-2023-2927CRITICAL9.8A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the f...
CVE-2023-2924CRITICAL9.8A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this ...
CVE-2023-2923CRITICAL9.8A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability ...
CVE-2023-32321CRITICAL9.8CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee...
CVE-2023-21516CRITICAL9.6XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API ...
CVE-2023-30145CRITICAL9.8Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para...
CVE-2023-32074CRITICAL9.8user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. I...
CVE-2023-33280CRITICAL9.8In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be execut...
CVE-2023-33279CRITICAL9.8In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed w...
CVE-2023-33278CRITICAL9.8In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a...
CVE-2023-2851CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron...
CVE-2023-2887CRITICAL9.8Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbo...
CVE-2023-2884CRITICAL9.8Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability i...
CVE-2023-2882CRITICAL9.8Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This...
CVE-2023-2734CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This...
CVE-2023-2733CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now