2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47435 | CRITICAL | 9.8 | 0.6% | Apr 19, 2024 | An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access... |
| CVE-2023-49742 | CRITICAL | 9.9 | 0.8% | Apr 18, 2024 | Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3. |
| CVE-2023-40146 | CRITICAL | 9.8 | 1.4% | Apr 17, 2024 | A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A ... |
| CVE-2023-48710 | CRITICAL | 9.8 | 0.7% | Apr 15, 2024 | iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho... |
| CVE-2023-51409 | CRITICAL | 9.8 | 63.3% | Apr 12, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect... |
| CVE-2023-50347 | CRITICAL | 9.8 | 0.6% | Apr 10, 2024 | HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability... |
| CVE-2023-49134 | CRITICAL | 9.8 | 1.7% | Apr 9, 2024 | A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO ... |
| CVE-2023-49133 | CRITICAL | 9.8 | 1.7% | Apr 9, 2024 | A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO ... |
| CVE-2023-6317 | CRITICAL | 9.8 | 1.1% | Apr 9, 2024 | A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create ... |
| CVE-2023-1083 | CRITICAL | 9.8 | 0.7% | Apr 9, 2024 | An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET c... |
| CVE-2023-52538 | CRITICAL | 9.1 | 0.3% | Apr 8, 2024 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this v... |
| CVE-2023-48426 | CRITICAL | 10 | 0.2% | Apr 5, 2024 | u-boot bug that allows for u-boot shell and interrupt over UART |
| CVE-2023-3454 | CRITICAL | 9.8 | 1.2% | Apr 4, 2024 | Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to e... |
| CVE-2023-36645 | CRITICAL | 9.8 | 0.9% | Apr 4, 2024 | SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow compone... |
| CVE-2023-44039 | CRITICAL | 9.1 | 0.5% | Apr 3, 2024 | In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifi... |
| CVE-2023-25699 | CRITICAL | 9.8 | 1.3% | Apr 3, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper... |
| CVE-2023-51573 | CRITICAL | 9.8 | 45.7% | Apr 1, 2024 | Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This... |
| CVE-2023-51572 | CRITICAL | 9.8 | 38.4% | Apr 1, 2024 | Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2023-51570 | CRITICAL | 9.8 | 1.0% | Apr 1, 2024 | Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2023-51803 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" subst... |
| CVE-2023-46808 | CRITICAL | 9.9 | 2.0% | Mar 31, 2024 | An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to... |
| CVE-2023-49232 | CRITICAL | 9.8 | 1.5% | Mar 29, 2024 | An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to b... |
| CVE-2023-49231 | CRITICAL | 9.8 | 42.9% | Mar 29, 2024 | An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to r... |
| CVE-2023-6191 | CRITICAL | 9.8 | 0.6% | Mar 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security We... |
| CVE-2023-50969 | CRITICAL | 9.8 | 0.9% | Mar 28, 2024 | Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a diff... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now