2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-21459CRITICAL9.8Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fau...
CVE-2023-21455CRITICAL9.1Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of un...
CVE-2023-0598CRITICAL9.8 GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code inj...
CVE-2023-1256CRITICAL9.8The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit ...
CVE-2023-0811CRITICAL9.1 Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an...
CVE-2023-28110CRITICAL9.9Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, ref...
CVE-2023-27041CRITICAL9.8School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/...
CVE-2023-27040CRITICAL9.8Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username paramet...
CVE-2023-27250CRITICAL9.8Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
CVE-2023-1432CRITICAL9.8A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this...
CVE-2023-26784CRITICAL9.8SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v...
CVE-2023-24795CRITICAL9.8Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
CVE-2023-23150CRITICAL9.8SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.
CVE-2023-25280CRITICAL9.8OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr...
CVE-2023-28461CRITICAL9.8Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the ...
CVE-2023-24468CRITICAL9.8Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
CVE-2023-25344CRITICAL9.8An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via...
CVE-2023-1416CRITICAL9.8A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the ...
CVE-2023-1379CRITICAL9.8A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as ...
CVE-2023-24726CRITICAL9.8Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on t...
CVE-2023-27240CRITICAL9.8Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/Ad...
CVE-2023-27239CRITICAL9.8Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
CVE-2023-28371CRITICAL9.8In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathna...
CVE-2023-27757CRITICAL9.8An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to ...
CVE-2023-1327CRITICAL9.8Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an u...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now