2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2523 | CRITICAL | 9.8 | 32.9% | May 4, 2023 | A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown ... |
| CVE-2023-30203 | CRITICAL | 9.8 | 0.8% | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /ph... |
| CVE-2023-2520 | CRITICAL | 9.8 | 2.6% | May 4, 2023 | A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affect... |
| CVE-2023-2519 | CRITICAL | 9.8 | 0.6% | May 4, 2023 | A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects un... |
| CVE-2023-29827 | CRITICAL | 9.8 | 5.6% | May 4, 2023 | ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be i... |
| CVE-2023-22651 | CRITICAL | 9.9 | 0.8% | May 4, 2023 | Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o... |
| CVE-2023-30331 | CRITICAL | 9.8 | 0.9% | May 4, 2023 | An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a... |
| CVE-2023-30077 | CRITICAL | 9.8 | 0.8% | May 4, 2023 | Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php... |
| CVE-2023-22637 | CRITICAL | 9 | 0.6% | May 3, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiN... |
| CVE-2023-30204 | CRITICAL | 9.8 | 0.6% | May 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /ph... |
| CVE-2023-25826 | CRITICAL | 9.8 | 35.6% | May 3, 2023 | Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS co... |
| CVE-2023-29778 | CRITICAL | 9.8 | 17.7% | May 2, 2023 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. |
| CVE-2023-26089 | CRITICAL | 9.8 | 1.1% | May 2, 2023 | European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used... |
| CVE-2023-2479 | CRITICAL | 9.8 | 22.0% | May 2, 2023 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. |
| CVE-2023-29856 | CRITICAL | 9.8 | 0.9% | May 2, 2023 | D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in sca... |
| CVE-2023-30869 | CRITICAL | 9.8 | 3.1% | May 2, 2023 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a... |
| CVE-2023-1730 | CRITICAL | 9.8 | 40.6% | May 2, 2023 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme... |
| CVE-2023-2451 | CRITICAL | 9.8 | 0.7% | May 1, 2023 | A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affec... |
| CVE-2023-29635 | CRITICAL | 9.8 | 1.1% | May 1, 2023 | File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file... |
| CVE-2023-30859 | CRITICAL | 9.8 | 1.1% | May 1, 2023 | Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload... |
| CVE-2023-2429 | CRITICAL | 9.8 | 0.5% | Apr 30, 2023 | Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13. |
| CVE-2023-2420 | CRITICAL | 9.8 | 0.7% | Apr 29, 2023 | A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the l... |
| CVE-2023-31470 | CRITICAL | 9.8 | 1.1% | Apr 28, 2023 | SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_en... |
| CVE-2023-26813 | CRITICAL | 9.8 | 1.0% | Apr 28, 2023 | SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java ... |
| CVE-2023-26781 | CRITICAL | 9.8 | 1.0% | Apr 28, 2023 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reade... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now