2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42286 | CRITICAL | 9.8 | 1.0% | Mar 14, 2024 | There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execu... |
| CVE-2023-38535 | CRITICAL | 9.8 | 0.3% | Mar 13, 2024 | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The ... |
| CVE-2023-41505 | CRITICAL | 9.8 | 0.8% | Mar 13, 2024 | An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 a... |
| CVE-2023-6825 | CRITICAL | 9.9 | 6.0% | Mar 13, 2024 | The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and... |
| CVE-2023-48788 | CRITICAL | 9.8 | 97.6% | Mar 12, 2024 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio... |
| CVE-2023-42789 | CRITICAL | 9.8 | 3.3% | Mar 12, 2024 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 ... |
| CVE-2023-36554 | CRITICAL | 9.8 | 0.8% | Mar 12, 2024 | A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0... |
| CVE-2023-41313 | CRITICAL | 9.8 | 1.0% | Mar 12, 2024 | The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended ... |
| CVE-2023-49785 | CRITICAL | 9.8 | 83.2% | Mar 12, 2024 | NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 ... |
| CVE-2023-46427 | CRITICAL | 9.8 | 1.1% | Mar 9, 2024 | An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary c... |
| CVE-2023-49340 | CRITICAL | 9.8 | 0.9% | Mar 9, 2024 | An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers ... |
| CVE-2023-46172 | CRITICAL | 9.8 | 0.5% | Mar 7, 2024 | IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass a... |
| CVE-2023-41503 | CRITICAL | 9.8 | 0.6% | Mar 7, 2024 | Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function. |
| CVE-2023-41014 | CRITICAL | 9.8 | 0.6% | Mar 7, 2024 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." |
| CVE-2023-51786 | CRITICAL | 9.1 | 0.5% | Mar 7, 2024 | An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privil... |
| CVE-2023-49989 | CRITICAL | 9.8 | 0.8% | Mar 7, 2024 | Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php... |
| CVE-2023-50716 | CRITICAL | 9.8 | 0.7% | Mar 6, 2024 | eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object M... |
| CVE-2023-38945 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Mul... |
| CVE-2023-38944 | CRITICAL | 9.8 | 15.5% | Mar 6, 2024 | An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers t... |
| CVE-2023-7103 | CRITICAL | 9.8 | 0.6% | Mar 5, 2024 | Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authen... |
| CVE-2023-5457 | CRITICAL | 9.8 | 0.6% | Mar 5, 2024 | A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web app... |
| CVE-2023-45600 | CRITICAL | 9.8 | 0.4% | Mar 5, 2024 | A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” ... |
| CVE-2023-45597 | CRITICAL | 9 | 0.4% | Mar 5, 2024 | A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functio... |
| CVE-2023-45592 | CRITICAL | 9.8 | 0.7% | Mar 5, 2024 | A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary bein... |
| CVE-2023-5456 | CRITICAL | 9.8 | 0.6% | Mar 5, 2024 | A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote u... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now