2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-28769CRITICAL9.8The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware v...
CVE-2023-28697CRITICAL9.8Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vu...
CVE-2023-20853CRITICAL9.8aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message ...
CVE-2023-20852CRITICAL9.8aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauth...
CVE-2023-30845CRITICAL9.8ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 thr...
CVE-2023-30363CRITICAL9.8vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions...
CVE-2023-30280CRITICAL9.8Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote a...
CVE-2023-29268CRITICAL9.8The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that all...
CVE-2023-30211CRITICAL9.8OURPHP <= 7.2.0 is vulnerable to SQL Injection.
CVE-2023-24796CRITICAL9.8Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary c...
CVE-2023-30404CRITICAL9.8Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability ...
CVE-2023-27843CRITICAL9.8SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileg...
CVE-2023-30838CRITICAL9.9PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isClean...
CVE-2023-25313CRITICAL9.8OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbit...
CVE-2023-27105CRITICAL9.8A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and...
CVE-2023-28771CRITICAL9.8Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers...
CVE-2023-1020CRITICAL9.8The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using i...
CVE-2023-29566CRITICAL9.8huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (...
CVE-2023-27849CRITICAL9.8rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process ...
CVE-2023-27848CRITICAL9.8broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process func...
CVE-2023-26865CRITICAL9.8SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privilege...
CVE-2023-30613CRITICAL9Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In ...
CVE-2023-27524CRITICAL9.8Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered th...
CVE-2023-24823CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc...
CVE-2023-30378CRITICAL9.8In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now