2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1283 | CRITICAL | 9.8 | 1.1% | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. |
| CVE-2023-24782 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit... |
| CVE-2023-22889 | CRITICAL | 9.8 | 1.3% | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re... |
| CVE-2023-26489 | CRITICAL | 9.9 | 1.3% | Mar 8, 2023 | wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a ... |
| CVE-2023-27482 | CRITICAL | 10 | 72.0% | Mar 8, 2023 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for ... |
| CVE-2023-26922 | CRITICAL | 9.8 | 1.2% | Mar 8, 2023 | SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the... |
| CVE-2023-24773 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list... |
| CVE-2023-26261 | CRITICAL | 9.8 | 0.8% | Mar 8, 2023 | In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the sess... |
| CVE-2023-25395 | CRITICAL | 9.8 | 1.9% | Mar 8, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou par... |
| CVE-2023-1267 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company Ptte... |
| CVE-2023-23638 | CRITICAL | 9.8 | 4.8% | Mar 8, 2023 | A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This ... |
| CVE-2023-1269 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-0090 | CRITICAL | 9.8 | 0.7% | Mar 8, 2023 | The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user ... |
| CVE-2023-24780 | CRITICAL | 9.8 | 0.8% | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns... |
| CVE-2023-27479 | CRITICAL | 9.9 | 1.1% | Mar 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2023-24775 | CRITICAL | 9.8 | 18.9% | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member... |
| CVE-2023-25690 | CRITICAL | 9.8 | 83.8% | Mar 7, 2023 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.... |
| CVE-2023-24781 | CRITICAL | 9.8 | 0.7% | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member... |
| CVE-2023-1253 | CRITICAL | 9.8 | 0.8% | Mar 7, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management S... |
| CVE-2023-26949 | CRITICAL | 9.8 | 0.9% | Mar 6, 2023 | An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to ... |
| CVE-2023-24736 | CRITICAL | 9.8 | 1.6% | Mar 6, 2023 | PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_... |
| CVE-2023-24734 | CRITICAL | 9.8 | 20.7% | Mar 6, 2023 | An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbi... |
| CVE-2023-24776 | CRITICAL | 9.8 | 1.4% | Mar 6, 2023 | Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addo... |
| CVE-2023-0979 | CRITICAL | 9.8 | 0.7% | Mar 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPAC... |
| CVE-2023-0839 | CRITICAL | 9.8 | 0.6% | Mar 6, 2023 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Acc... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now