2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-26511CRITICAL9.8A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote ...
CVE-2023-28343CRITICAL9.8OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen...
CVE-2023-23415CRITICAL9.8Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
CVE-2023-23397CRITICAL9.8Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-23392CRITICAL9.8HTTP Protocol Stack Remote Code Execution Vulnerability
CVE-2023-21708CRITICAL9.8Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-27074CRITICAL9.8BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter i...
CVE-2023-1394CRITICAL9.8A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This ...
CVE-2023-1392CRITICAL9.8A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected b...
CVE-2023-1391CRITICAL9.8A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management Syst...
CVE-2023-27501CRITICAL9.6SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, ...
CVE-2023-27269CRITICAL9.6SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,...
CVE-2023-27582CRITICAL9.8maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a fu...
CVE-2023-27052CRITICAL9.8E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user...
CVE-2023-27583CRITICAL9.8PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used...
CVE-2023-0354CRITICAL9.1The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access se...
CVE-2023-0353CRITICAL9.8Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which cou...
CVE-2023-0352CRITICAL9.1The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the devi...
CVE-2023-0349CRITICAL9.1The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image and video. This could al...
CVE-2023-0345CRITICAL9.8The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password canno...
CVE-2023-25207CRITICAL9.8PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
CVE-2023-25279CRITICAL9.8OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr...
CVE-2023-1378CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0...
CVE-2023-0037CRITICAL9.8The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some paramete...
CVE-2023-26076CRITICAL9.8An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now