2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-2215CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown fu...
CVE-2023-2206CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects...
CVE-2023-1892CRITICAL9.6Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVE-2023-2131CRITICAL9.8Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to ...
CVE-2023-20873CRITICAL9.8In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed t...
CVE-2023-20864CRITICAL9.8VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo...
CVE-2023-30076CRITICAL9.8Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges....
CVE-2023-29528CRITICAL9XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM...
CVE-2023-27350CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui...
CVE-2023-29926CRITICAL9.8PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
CVE-2023-2193CRITICAL9.1Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker posse...
CVE-2023-23451CRITICAL9.8The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmwar...
CVE-2023-21096CRITICAL9.8In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution wi...
CVE-2023-2136CRITICAL9.6Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the rend...
CVE-2023-28004CRITICAL9.8 A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul...
CVE-2023-29412CRITICAL9.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2023-29411CRITICAL9.8 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative...
CVE-2023-28839CRITICAL9.8Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed f...
CVE-2023-25550CRITICAL9.8 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote cod...
CVE-2023-25549CRITICAL9.8 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote c...
CVE-2023-2160CRITICAL9.8Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-2152CRITICAL9.8A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as criti...
CVE-2023-28863CRITICAL9.1AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
CVE-2023-2151CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management Syst...
CVE-2023-2149CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability aff...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now