2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28769 | CRITICAL | 9.8 | 5.4% | Apr 27, 2023 | The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware v... |
| CVE-2023-28697 | CRITICAL | 9.8 | 0.9% | Apr 27, 2023 | Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vu... |
| CVE-2023-20853 | CRITICAL | 9.8 | 1.0% | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message ... |
| CVE-2023-20852 | CRITICAL | 9.8 | 1.0% | Apr 27, 2023 | aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauth... |
| CVE-2023-30845 | CRITICAL | 9.8 | 0.7% | Apr 26, 2023 | ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 thr... |
| CVE-2023-30363 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions... |
| CVE-2023-30280 | CRITICAL | 9.8 | 1.2% | Apr 26, 2023 | Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote a... |
| CVE-2023-29268 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that all... |
| CVE-2023-30211 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to SQL Injection. |
| CVE-2023-24796 | CRITICAL | 9.8 | 1.6% | Apr 26, 2023 | Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary c... |
| CVE-2023-30404 | CRITICAL | 9.8 | 2.4% | Apr 26, 2023 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability ... |
| CVE-2023-27843 | CRITICAL | 9.8 | 1.2% | Apr 26, 2023 | SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileg... |
| CVE-2023-30838 | CRITICAL | 9.9 | 1.0% | Apr 25, 2023 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isClean... |
| CVE-2023-25313 | CRITICAL | 9.8 | 1.3% | Apr 25, 2023 | OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbit... |
| CVE-2023-27105 | CRITICAL | 9.8 | 1.3% | Apr 25, 2023 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and... |
| CVE-2023-28771 | CRITICAL | 9.8 | 99.3% | Apr 25, 2023 | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers... |
| CVE-2023-1020 | CRITICAL | 9.8 | 5.0% | Apr 24, 2023 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using i... |
| CVE-2023-29566 | CRITICAL | 9.8 | 2.2% | Apr 24, 2023 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (... |
| CVE-2023-27849 | CRITICAL | 9.8 | 1.8% | Apr 24, 2023 | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process ... |
| CVE-2023-27848 | CRITICAL | 9.8 | 1.9% | Apr 24, 2023 | broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process func... |
| CVE-2023-26865 | CRITICAL | 9.8 | 1.2% | Apr 24, 2023 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privilege... |
| CVE-2023-30613 | CRITICAL | 9 | 1.0% | Apr 24, 2023 | Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In ... |
| CVE-2023-27524 | CRITICAL | 9.8 | 97.4% | Apr 24, 2023 | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered th... |
| CVE-2023-24823 | CRITICAL | 9.8 | 1.0% | Apr 24, 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc... |
| CVE-2023-30378 | CRITICAL | 9.8 | 0.8% | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now