2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2732 | CRITICAL | 9.8 | 67.5% | May 25, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This... |
| CVE-2023-31458 | CRITICAL | 9.8 | 0.9% | May 24, 2023 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier coul... |
| CVE-2023-29721 | CRITICAL | 9.8 | 1.1% | May 24, 2023 | SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution. |
| CVE-2023-33796 | CRITICAL | 9.1 | 0.7% | May 24, 2023 | A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, grant... |
| CVE-2023-31457 | CRITICAL | 9.8 | 1.0% | May 24, 2023 | A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earli... |
| CVE-2023-2868 | CRITICAL | 9.8 | 87.0% | May 24, 2023 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) pro... |
| CVE-2023-1174 | CRITICAL | 9.8 | 0.8% | May 24, 2023 | This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected r... |
| CVE-2023-33246 | CRITICAL | 9.8 | 96.6% | May 24, 2023 | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several ... |
| CVE-2023-2064 | CRITICAL | 9.8 | 0.6% | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology ... |
| CVE-2023-2045 | CRITICAL | 9.8 | 0.6% | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software ... |
| CVE-2023-33010 | CRITICAL | 9.8 | 28.8% | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Pa... |
| CVE-2023-33009 | CRITICAL | 9.8 | 28.1% | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Pat... |
| CVE-2023-2750 | CRITICAL | 9.8 | 0.6% | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municip... |
| CVE-2023-2865 | CRITICAL | 9.8 | 0.7% | May 24, 2023 | A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This af... |
| CVE-2023-32697 | CRITICAL | 9.8 | 1.6% | May 23, 2023 | SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code e... |
| CVE-2023-1508 | CRITICAL | 9.8 | 0.6% | May 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automa... |
| CVE-2023-31752 | CRITICAL | 9.8 | 0.8% | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/... |
| CVE-2023-23306 | CRITICAL | 9.8 | 1.2% | May 23, 2023 | The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnre... |
| CVE-2023-23305 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading... |
| CVE-2023-23304 | CRITICAL | 9.1 | 0.6% | May 23, 2023 | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head sect... |
| CVE-2023-23303 | CRITICAL | 9.8 | 0.8% | May 23, 2023 | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its... |
| CVE-2023-23302 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its para... |
| CVE-2023-23301 | CRITICAL | 9.8 | 1.1% | May 23, 2023 | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not ex... |
| CVE-2023-23300 | CRITICAL | 9.8 | 1.3% | May 23, 2023 | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its para... |
| CVE-2023-23298 | CRITICAL | 9.8 | 1.5% | May 23, 2023 | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now