2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-33362CRITICAL9.8Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
CVE-2023-33361CRITICAL9.8Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
CVE-2023-33338CRITICAL9.8Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
CVE-2023-28413CRITICAL9.8Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attac...
CVE-2023-28409CRITICAL9.8Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remo...
CVE-2023-28408CRITICAL9.8Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to ...
CVE-2023-27507CRITICAL9.8MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload functi...
CVE-2023-27397CRITICAL9.8Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's ...
CVE-2023-27388CRITICAL9.8Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauth...
CVE-2023-25953CRITICAL9.8Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to ...
CVE-2023-31814CRITICAL9.8D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
CVE-2023-29919CRITICAL9.1SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t...
CVE-2023-27068CRITICAL9.8Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary ...
CVE-2023-2504CRITICAL9.8 Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-code...
CVE-2023-31689CRITICAL9.8In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.ph...
CVE-2023-31241CRITICAL10Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
CVE-2023-31240CRITICAL9.8Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network...
CVE-2023-28386CRITICAL9.8Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates ...
CVE-2023-2840CRITICAL9.8NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
CVE-2023-2838CRITICAL9.1Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
CVE-2023-33294CRITICAL9.8An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that re...
CVE-2023-31098CRITICAL9.8Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: f...
CVE-2023-31066CRITICAL9.1Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue...
CVE-2023-31065CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLo...
CVE-2023-31062CRITICAL9.8Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now