2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1684 | CRITICAL | 9.8 | 0.9% | Mar 29, 2023 | A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the f... |
| CVE-2023-27232 | CRITICAL | 9.8 | 1.9% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy p... |
| CVE-2023-27231 | CRITICAL | 9.8 | 2.0% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parame... |
| CVE-2023-27229 | CRITICAL | 9.8 | 2.0% | Mar 28, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw paramete... |
| CVE-2023-28712 | CRITICAL | 9.8 | 1.2% | Mar 28, 2023 | Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system ... |
| CVE-2023-28654 | CRITICAL | 9.8 | 0.8% | Mar 28, 2023 | Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full... |
| CVE-2023-28631 | CRITICAL | 9.8 | 1.3% | Mar 28, 2023 | comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A Comrak AST can be constructed ma... |
| CVE-2023-28398 | CRITICAL | 9.8 | 0.9% | Mar 28, 2023 | Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, ... |
| CVE-2023-27886 | CRITICAL | 9.8 | 1.7% | Mar 28, 2023 | Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be ... |
| CVE-2023-27394 | CRITICAL | 9.8 | 18.2% | Mar 28, 2023 | Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exp... |
| CVE-2023-1675 | CRITICAL | 9.8 | 0.8% | Mar 28, 2023 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. It has been classified as critical. ... |
| CVE-2023-1674 | CRITICAL | 9.8 | 0.9% | Mar 28, 2023 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0 and classified as critical. This issu... |
| CVE-2023-27821 | CRITICAL | 9.8 | 1.5% | Mar 28, 2023 | Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter. |
| CVE-2023-28326 | CRITICAL | 9.8 | 1.3% | Mar 28, 2023 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Att... |
| CVE-2023-28102 | CRITICAL | 9.6 | 2.5% | Mar 27, 2023 | discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` ... |
| CVE-2023-1665 | CRITICAL | 9.8 | 0.6% | Mar 27, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0. |
| CVE-2023-25261 | CRITICAL | 9.8 | 2.3% | Mar 27, 2023 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023... |
| CVE-2023-1666 | CRITICAL | 9.8 | 0.7% | Mar 27, 2023 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critica... |
| CVE-2023-27847 | CRITICAL | 9.8 | 4.7% | Mar 27, 2023 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi... |
| CVE-2023-1399 | CRITICAL | 9.8 | 0.8% | Mar 27, 2023 | N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious ... |
| CVE-2023-1142 | CRITICAL | 9.8 | 1.1% | Mar 27, 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve sy... |
| CVE-2023-1140 | CRITICAL | 9.8 | 1.1% | Mar 27, 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker ... |
| CVE-2023-1133 | CRITICAL | 9.8 | 50.0% | Mar 27, 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status se... |
| CVE-2023-26959 | CRITICAL | 9.8 | 0.8% | Mar 27, 2023 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter. |
| CVE-2023-25909 | CRITICAL | 9.8 | 0.9% | Mar 27, 2023 | HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now