2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20160 | CRITICAL | 9.8 | 10.3% | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an ... |
| CVE-2023-20159 | CRITICAL | 9.8 | 10.3% | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an ... |
| CVE-2023-20158 | CRITICAL | 9.8 | 1.2% | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an ... |
| CVE-2023-20157 | CRITICAL | 9.8 | 1.2% | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an ... |
| CVE-2023-20156 | CRITICAL | 9.8 | 1.2% | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an ... |
| CVE-2023-31729 | CRITICAL | 9.8 | 1.8% | May 18, 2023 | TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. |
| CVE-2023-29985 | CRITICAL | 9.8 | 0.9% | May 18, 2023 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vu... |
| CVE-2023-2319 | CRITICAL | 9.8 | 1.0% | May 17, 2023 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux ... |
| CVE-2023-2780 | CRITICAL | 9.8 | 6.3% | May 17, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. |
| CVE-2023-30191 | CRITICAL | 9.8 | 0.8% | May 17, 2023 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). |
| CVE-2023-2776 | CRITICAL | 9.8 | 0.7% | May 17, 2023 | A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerabilit... |
| CVE-2023-2774 | CRITICAL | 9.8 | 0.7% | May 17, 2023 | A vulnerability was found in code-projects Bus Dispatch and Information System 1.0 and classified as critical. Affected ... |
| CVE-2023-31903 | CRITICAL | 9.8 | 2.1% | May 17, 2023 | GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by u... |
| CVE-2023-31902 | CRITICAL | 9.8 | 8.7% | May 17, 2023 | RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE). |
| CVE-2023-31703 | CRITICAL | 9 | 4.5% | May 17, 2023 | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo... |
| CVE-2023-30189 | CRITICAL | 9.8 | 0.8% | May 16, 2023 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). |
| CVE-2023-27742 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login. |
| CVE-2023-31890 | CRITICAL | 9.8 | 1.0% | May 16, 2023 | An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXML... |
| CVE-2023-31857 | CRITICAL | 9.8 | 1.5% | May 16, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code executio... |
| CVE-2023-31856 | CRITICAL | 9.8 | 2.9% | May 16, 2023 | A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.759... |
| CVE-2023-31587 | CRITICAL | 9.8 | 2.0% | May 16, 2023 | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac paramete... |
| CVE-2023-31519 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login... |
| CVE-2023-2738 | CRITICAL | 9.8 | 0.9% | May 16, 2023 | A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the... |
| CVE-2023-2499 | CRITICAL | 9.8 | 1.3% | May 16, 2023 | The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.... |
| CVE-2023-32956 | CRITICAL | 9.8 | 1.5% | May 16, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI componen... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now