2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-2732CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This...
CVE-2023-31458CRITICAL9.8A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier coul...
CVE-2023-29721CRITICAL9.8SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
CVE-2023-33796CRITICAL9.1A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, grant...
CVE-2023-31457CRITICAL9.8A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earli...
CVE-2023-2868CRITICAL9.8A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) pro...
CVE-2023-1174CRITICAL9.8This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected r...
CVE-2023-33246CRITICAL9.8For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several ...
CVE-2023-2064CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology ...
CVE-2023-2045CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software ...
CVE-2023-33010CRITICAL9.8A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Pa...
CVE-2023-33009CRITICAL9.8A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Pat...
CVE-2023-2750CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municip...
CVE-2023-2865CRITICAL9.8A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This af...
CVE-2023-32697CRITICAL9.8SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code e...
CVE-2023-1508CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automa...
CVE-2023-31752CRITICAL9.8SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/...
CVE-2023-23306CRITICAL9.8The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnre...
CVE-2023-23305CRITICAL9.8The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading...
CVE-2023-23304CRITICAL9.1The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head sect...
CVE-2023-23303CRITICAL9.8The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its...
CVE-2023-23302CRITICAL9.8The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its para...
CVE-2023-23301CRITICAL9.8The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not ex...
CVE-2023-23300CRITICAL9.8The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its para...
CVE-2023-23298CRITICAL9.8The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now