2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1650 | CRITICAL | 9.8 | 34.4% | May 8, 2023 | The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauth... |
| CVE-2023-25754 | CRITICAL | 9.8 | 2.3% | May 8, 2023 | Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache A... |
| CVE-2023-31039 | CRITICAL | 9.8 | 1.5% | May 8, 2023 | Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptio... |
| CVE-2023-30018 | CRITICAL | 9.8 | 0.8% | May 8, 2023 | Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. |
| CVE-2023-30185 | CRITICAL | 9.8 | 1.3% | May 8, 2023 | CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System... |
| CVE-2023-29944 | CRITICAL | 9.8 | 2.1% | May 8, 2023 | Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be exe... |
| CVE-2023-2564 | CRITICAL | 10 | 40.5% | May 7, 2023 | OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. |
| CVE-2023-31047 | CRITICAL | 9.8 | 1.4% | May 7, 2023 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one... |
| CVE-2023-30054 | CRITICAL | 9.8 | 2.1% | May 5, 2023 | TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell... |
| CVE-2023-30053 | CRITICAL | 9.8 | 2.1% | May 5, 2023 | TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection. |
| CVE-2023-30013 | CRITICAL | 9.8 | 25.9% | May 5, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s... |
| CVE-2023-30242 | CRITICAL | 9.8 | 0.7% | May 5, 2023 | NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. |
| CVE-2023-30090 | CRITICAL | 9.8 | 0.8% | May 5, 2023 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. T... |
| CVE-2023-30135 | CRITICAL | 9.8 | 2.4% | May 5, 2023 | Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName paramet... |
| CVE-2023-30122 | CRITICAL | 9.8 | 1.0% | May 5, 2023 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System ... |
| CVE-2023-2531 | CRITICAL | 9.8 | 0.8% | May 5, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3. |
| CVE-2023-30328 | CRITICAL | 9.8 | 1.1% | May 4, 2023 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authenticati... |
| CVE-2023-21504 | CRITICAL | 9.8 | 0.6% | May 4, 2023 | Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 all... |
| CVE-2023-21503 | CRITICAL | 9.8 | 0.6% | May 4, 2023 | Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release ... |
| CVE-2023-21494 | CRITICAL | 9.8 | 0.7% | May 4, 2023 | Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Rel... |
| CVE-2023-30268 | CRITICAL | 9.8 | 0.8% | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation. |
| CVE-2023-30264 | CRITICAL | 9.8 | 0.7% | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.... |
| CVE-2023-23059 | CRITICAL | 9.8 | 1.5% | May 4, 2023 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions ... |
| CVE-2023-20126 | CRITICAL | 9.8 | 38.1% | May 4, 2023 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticat... |
| CVE-2023-2524 | CRITICAL | 9.8 | 0.4% | May 4, 2023 | A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now