2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-42286CRITICAL9.8There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execu...
CVE-2023-38535CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The ...
CVE-2023-41505CRITICAL9.8An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 a...
CVE-2023-6825CRITICAL9.9The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and...
CVE-2023-48788CRITICAL9.8A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio...
CVE-2023-42789CRITICAL9.8A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 ...
CVE-2023-36554CRITICAL9.8A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0...
CVE-2023-41313CRITICAL9.8The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended ...
CVE-2023-49785CRITICAL9.8NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 ...
CVE-2023-46427CRITICAL9.8An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary c...
CVE-2023-49340CRITICAL9.8An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers ...
CVE-2023-46172CRITICAL9.8IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass a...
CVE-2023-41503CRITICAL9.8Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
CVE-2023-41014CRITICAL9.8code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."
CVE-2023-51786CRITICAL9.1An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privil...
CVE-2023-49989CRITICAL9.8Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php...
CVE-2023-50716CRITICAL9.8eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object M...
CVE-2023-38945CRITICAL9.8Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Mul...
CVE-2023-38944CRITICAL9.8An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers t...
CVE-2023-7103CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authen...
CVE-2023-5457CRITICAL9.8A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web app...
CVE-2023-45600CRITICAL9.8A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” ...
CVE-2023-45597CRITICAL9A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functio...
CVE-2023-45592CRITICAL9.8A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary bein...
CVE-2023-5456CRITICAL9.8A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote u...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now