2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24720 | CRITICAL | 9.8 | 1.1% | Apr 5, 2023 | An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a ... |
| CVE-2023-1782 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL autho... |
| CVE-2023-1886 | CRITICAL | 9.8 | 0.9% | Apr 5, 2023 | Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12. |
| CVE-2023-1877 | CRITICAL | 9.8 | 1.8% | Apr 5, 2023 | Command Injection in GitHub repository microweber/microweber prior to 1.3.3. |
| CVE-2023-20073 | CRITICAL | 9.8 | 88.9% | Apr 5, 2023 | A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Rou... |
| CVE-2023-1788 | CRITICAL | 9.8 | 0.4% | Apr 5, 2023 | Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. |
| CVE-2023-25330 | CRITICAL | 9.8 | 1.2% | Apr 5, 2023 | A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2023-1856 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability has been found in SourceCodester Air Cargo Management System 1.0 and classified as critical. Affected by... |
| CVE-2023-1854 | CRITICAL | 9.8 | 0.9% | Apr 5, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff... |
| CVE-2023-1850 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been rated as critical. Affected by this i... |
| CVE-2023-1849 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been declared as critical. Affected by thi... |
| CVE-2023-1848 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been classified as critical. Affected is a... |
| CVE-2023-1847 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability was found in SourceCodester Online Payroll System 1.0 and classified as critical. This issue affects som... |
| CVE-2023-1846 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability has been found in SourceCodester Online Payroll System 1.0 and classified as critical. This vulnerabilit... |
| CVE-2023-1845 | CRITICAL | 9.8 | 0.8% | Apr 5, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Online Payroll System 1.0. This affects a... |
| CVE-2023-29374 | CRITICAL | 9.8 | 39.7% | Apr 5, 2023 | In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via... |
| CVE-2023-27493 | CRITICAL | 9.1 | 0.5% | Apr 4, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,... |
| CVE-2023-27491 | CRITICAL | 9.1 | 0.9% | Apr 4, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should r... |
| CVE-2023-27488 | CRITICAL | 9.8 | 0.7% | Apr 4, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,... |
| CVE-2023-1748 | CRITICAL | 10 | 0.8% | Apr 4, 2023 | The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to th... |
| CVE-2023-28613 | CRITICAL | 9.8 | 1.2% | Apr 4, 2023 | An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, an... |
| CVE-2023-27487 | CRITICAL | 9.1 | 0.6% | Apr 4, 2023 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,... |
| CVE-2023-26921 | CRITICAL | 9.8 | 2.7% | Apr 4, 2023 | OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd. |
| CVE-2023-26750 | CRITICAL | 9.8 | 1.8% | Apr 4, 2023 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execu... |
| CVE-2023-26866 | CRITICAL | 9.8 | 2.3% | Apr 4, 2023 | GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now