2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-2523CRITICAL9.8A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown ...
CVE-2023-30203CRITICAL9.8Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /ph...
CVE-2023-2520CRITICAL9.8A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affect...
CVE-2023-2519CRITICAL9.8A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects un...
CVE-2023-29827CRITICAL9.8ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be i...
CVE-2023-22651CRITICAL9.9Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o...
CVE-2023-30331CRITICAL9.8An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a...
CVE-2023-30077CRITICAL9.8Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php...
CVE-2023-22637CRITICAL9An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiN...
CVE-2023-30204CRITICAL9.8Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /ph...
CVE-2023-25826CRITICAL9.8Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS co...
CVE-2023-29778CRITICAL9.8GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
CVE-2023-26089CRITICAL9.8European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used...
CVE-2023-2479CRITICAL9.8OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.
CVE-2023-29856CRITICAL9.8D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in sca...
CVE-2023-30869CRITICAL9.8Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a...
CVE-2023-1730CRITICAL9.8The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme...
CVE-2023-2451CRITICAL9.8A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affec...
CVE-2023-29635CRITICAL9.8File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file...
CVE-2023-30859CRITICAL9.8Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload...
CVE-2023-2429CRITICAL9.8Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
CVE-2023-2420CRITICAL9.8A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the l...
CVE-2023-31470CRITICAL9.8SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_en...
CVE-2023-26813CRITICAL9.8SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java ...
CVE-2023-26781CRITICAL9.8SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reade...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now