2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-47435CRITICAL9.8An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access...
CVE-2023-49742CRITICAL9.9Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
CVE-2023-40146CRITICAL9.8A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A ...
CVE-2023-48710CRITICAL9.8iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho...
CVE-2023-51409CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect...
CVE-2023-50347CRITICAL9.8HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability...
CVE-2023-49134CRITICAL9.8A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO ...
CVE-2023-49133CRITICAL9.8A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO ...
CVE-2023-6317CRITICAL9.8A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create ...
CVE-2023-1083CRITICAL9.8An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET c...
CVE-2023-52538CRITICAL9.1Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this v...
CVE-2023-48426CRITICAL10u-boot bug that allows for u-boot shell and interrupt over UART
CVE-2023-3454CRITICAL9.8Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to e...
CVE-2023-36645CRITICAL9.8SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow compone...
CVE-2023-44039CRITICAL9.1In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifi...
CVE-2023-25699CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper...
CVE-2023-51573CRITICAL9.8Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This...
CVE-2023-51572CRITICAL9.8Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2023-51570CRITICAL9.8Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability ...
CVE-2023-51803CRITICAL9.8LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" subst...
CVE-2023-46808CRITICAL9.9An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to...
CVE-2023-49232CRITICAL9.8An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to b...
CVE-2023-49231CRITICAL9.8An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to r...
CVE-2023-6191CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security We...
CVE-2023-50969CRITICAL9.8Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a diff...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now