2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2037 | CRITICAL | 9.8 | 0.8% | Apr 14, 2023 | A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been classified as critical. This affects an un... |
| CVE-2023-29622 | CRITICAL | 9.8 | 1.7% | Apr 14, 2023 | Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /pu... |
| CVE-2023-26918 | CRITICAL | 9.8 | 6.1% | Apr 14, 2023 | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan ... |
| CVE-2023-27748 | CRITICAL | 9.8 | 0.7% | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attac... |
| CVE-2023-27746 | CRITICAL | 9.8 | 1.8% | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke... |
| CVE-2023-27667 | CRITICAL | 9.8 | 0.7% | Apr 13, 2023 | Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-27779 | CRITICAL | 9.8 | 1.0% | Apr 13, 2023 | AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form. |
| CVE-2023-29598 | CRITICAL | 9.8 | 0.7% | Apr 13, 2023 | lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php. |
| CVE-2023-27812 | CRITICAL | 9.1 | 1.2% | Apr 13, 2023 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. |
| CVE-2023-28121 | CRITICAL | 9.8 | 86.9% | Apr 12, 2023 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s... |
| CVE-2023-27830 | CRITICAL | 9 | 1.1% | Apr 12, 2023 | TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate fi... |
| CVE-2023-27032 | CRITICAL | 9.8 | 3.0% | Apr 12, 2023 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the compo... |
| CVE-2023-28808 | CRITICAL | 9.8 | 0.8% | Apr 11, 2023 | Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the ... |
| CVE-2023-28250 | CRITICAL | 9.8 | 2.0% | Apr 11, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
| CVE-2023-21554 | CRITICAL | 9.8 | 95.5% | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-1984 | CRITICAL | 9.8 | 0.8% | Apr 11, 2023 | A vulnerability classified as critical was found in SourceCodester Complaint Management System 1.0. This vulnerability a... |
| CVE-2023-1983 | CRITICAL | 9.8 | 0.7% | Apr 11, 2023 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected... |
| CVE-2023-27192 | CRITICAL | 9.8 | 1.2% | Apr 11, 2023 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe... |
| CVE-2023-0645 | CRITICAL | 9.1 | 0.6% | Apr 11, 2023 | An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read ... |
| CVE-2023-27645 | CRITICAL | 9.8 | 1.5% | Apr 11, 2023 | An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges v... |
| CVE-2023-28489 | CRITICAL | 9.8 | 2.8% | Apr 11, 2023 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver... |
| CVE-2023-29492 | CRITICAL | 9.8 | 2.7% | Apr 11, 2023 | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the servi... |
| CVE-2023-26122 | CRITICAL | 10 | 2.1% | Apr 11, 2023 | All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerabi... |
| CVE-2023-26121 | CRITICAL | 10 | 1.1% | Apr 11, 2023 | All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper s... |
| CVE-2023-28765 | CRITICAL | 9.8 | 14.9% | Apr 11, 2023 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - version... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now