2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-1283CRITICAL9.8Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
CVE-2023-24782CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit...
CVE-2023-22889CRITICAL9.8SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re...
CVE-2023-26489CRITICAL9.9wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a ...
CVE-2023-27482CRITICAL10homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for ...
CVE-2023-26922CRITICAL9.8SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the...
CVE-2023-24773CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list...
CVE-2023-26261CRITICAL9.8In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the sess...
CVE-2023-25395CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou par...
CVE-2023-1267CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company Ptte...
CVE-2023-23638CRITICAL9.8A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This ...
CVE-2023-1269CRITICAL9.8Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-0090CRITICAL9.8The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user ...
CVE-2023-24780CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns...
CVE-2023-27479CRITICAL9.9XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver...
CVE-2023-24775CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member...
CVE-2023-25690CRITICAL9.8Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack....
CVE-2023-24781CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member...
CVE-2023-1253CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management S...
CVE-2023-26949CRITICAL9.8An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to ...
CVE-2023-24736CRITICAL9.8PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_...
CVE-2023-24734CRITICAL9.8An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbi...
CVE-2023-24776CRITICAL9.8Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addo...
CVE-2023-0979CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPAC...
CVE-2023-0839CRITICAL9.8Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Acc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now