2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2215 | CRITICAL | 9.8 | 1.6% | Apr 21, 2023 | A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown fu... |
| CVE-2023-2206 | CRITICAL | 9.8 | 0.7% | Apr 21, 2023 | A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects... |
| CVE-2023-1892 | CRITICAL | 9.6 | 2.7% | Apr 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8. |
| CVE-2023-2131 | CRITICAL | 9.8 | 1.7% | Apr 20, 2023 | Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to ... |
| CVE-2023-20873 | CRITICAL | 9.8 | 1.1% | Apr 20, 2023 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed t... |
| CVE-2023-20864 | CRITICAL | 9.8 | 71.7% | Apr 20, 2023 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo... |
| CVE-2023-30076 | CRITICAL | 9.8 | 0.8% | Apr 20, 2023 | Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.... |
| CVE-2023-29528 | CRITICAL | 9 | 1.3% | Apr 20, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM... |
| CVE-2023-27350 | CRITICAL | 9.8 | 100.0% | Apr 20, 2023 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui... |
| CVE-2023-29926 | CRITICAL | 9.8 | 1.2% | Apr 20, 2023 | PowerJob V4.3.2 has unauthorized interface that causes remote code execution. |
| CVE-2023-2193 | CRITICAL | 9.1 | 0.6% | Apr 20, 2023 | Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker posse... |
| CVE-2023-23451 | CRITICAL | 9.8 | 0.6% | Apr 19, 2023 | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmwar... |
| CVE-2023-21096 | CRITICAL | 9.8 | 0.5% | Apr 19, 2023 | In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution wi... |
| CVE-2023-2136 | CRITICAL | 9.6 | 5.8% | Apr 19, 2023 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the rend... |
| CVE-2023-28004 | CRITICAL | 9.8 | 1.1% | Apr 18, 2023 | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul... |
| CVE-2023-29412 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2023-29411 | CRITICAL | 9.8 | 1.3% | Apr 18, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative... |
| CVE-2023-28839 | CRITICAL | 9.8 | 0.8% | Apr 18, 2023 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed f... |
| CVE-2023-25550 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote cod... |
| CVE-2023-25549 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote c... |
| CVE-2023-2160 | CRITICAL | 9.8 | 0.6% | Apr 18, 2023 | Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0. |
| CVE-2023-2152 | CRITICAL | 9.8 | 1.2% | Apr 18, 2023 | A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as criti... |
| CVE-2023-28863 | CRITICAL | 9.1 | 0.4% | Apr 18, 2023 | AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity. |
| CVE-2023-2151 | CRITICAL | 9.8 | 0.8% | Apr 18, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management Syst... |
| CVE-2023-2149 | CRITICAL | 9.8 | 0.8% | Apr 18, 2023 | A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability aff... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now