2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24838 | CRITICAL | 9.8 | 1.1% | Mar 27, 2023 | HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulne... |
| CVE-2023-28883 | CRITICAL | 9.8 | 0.7% | Mar 27, 2023 | In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. |
| CVE-2023-26802 | CRITICAL | 9.8 | 48.7% | Mar 26, 2023 | An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attac... |
| CVE-2023-26801 | CRITICAL | 9.8 | 69.7% | Mar 26, 2023 | LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discove... |
| CVE-2023-26800 | CRITICAL | 9.8 | 1.0% | Mar 26, 2023 | Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability v... |
| CVE-2023-1458 | CRITICAL | 9.8 | 3.3% | Mar 25, 2023 | A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vuln... |
| CVE-2023-1457 | CRITICAL | 9.8 | 1.9% | Mar 25, 2023 | A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unk... |
| CVE-2023-1456 | CRITICAL | 9.8 | 1.9% | Mar 25, 2023 | A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue af... |
| CVE-2023-1634 | CRITICAL | 9.8 | 0.7% | Mar 25, 2023 | A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the fil... |
| CVE-2023-28437 | CRITICAL | 9.8 | 0.9% | Mar 25, 2023 | Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing e... |
| CVE-2023-25668 | CRITICAL | 9.8 | 0.8% | Mar 25, 2023 | TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can acc... |
| CVE-2023-25664 | CRITICAL | 9.8 | 0.4% | Mar 25, 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer ... |
| CVE-2023-23149 | CRITICAL | 9.8 | 0.9% | Mar 24, 2023 | DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability. |
| CVE-2023-28150 | CRITICAL | 9.8 | 0.7% | Mar 24, 2023 | An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection ... |
| CVE-2023-26864 | CRITICAL | 9.8 | 1.2% | Mar 24, 2023 | SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to g... |
| CVE-2023-28151 | CRITICAL | 9.8 | 0.8% | Mar 24, 2023 | An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) in... |
| CVE-2023-21058 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. T... |
| CVE-2023-21057 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check.... |
| CVE-2023-20954 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could l... |
| CVE-2023-20951 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. Thi... |
| CVE-2023-28152 | CRITICAL | 9.8 | 0.7% | Mar 24, 2023 | An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection... |
| CVE-2023-1177 | CRITICAL | 9.8 | 69.5% | Mar 24, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. |
| CVE-2023-28445 | CRITICAL | 9.8 | 1.0% | Mar 24, 2023 | Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asyn... |
| CVE-2023-27034 | CRITICAL | 9.8 | 58.7% | Mar 23, 2023 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-28611 | CRITICAL | 9.8 | 0.6% | Mar 23, 2023 | Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now