2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-23453CRITICAL9.8Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged...
CVE-2023-23452CRITICAL9.8Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged...
CVE-2023-25805CRITICAL9.8versionn, software for changing version information across multiple files, has a command injection vulnerability in all ...
CVE-2023-25613CRITICAL9.8An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 
CVE-2023-26093CRITICAL9.8Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
CVE-2023-26092CRITICAL9.8Liima before 1.17.28 allows server-side template injection.
CVE-2023-0918CRITICAL9.8A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerabi...
CVE-2023-0917CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management S...
CVE-2023-0910CRITICAL9.8A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulne...
CVE-2023-0906CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vu...
CVE-2023-23064CRITICAL9.8TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
CVE-2023-23279CRITICAL9.8Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
CVE-2023-0883CRITICAL9.8A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulne...
CVE-2023-24221CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMa...
CVE-2023-24220CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMa...
CVE-2023-24219CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMa...
CVE-2023-24238CRITICAL9.8TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city paramet...
CVE-2023-24236CRITICAL9.8TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province par...
CVE-2023-22578CRITICAL9.8Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
CVE-2023-0849CRITICAL9.8A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unk...
CVE-2023-22855CRITICAL9.8Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 808...
CVE-2023-23462CRITICAL9.8Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).
CVE-2023-23461CRITICAL9.8Libpeconv – access violation, before commit b076013 (30/11/2022).
CVE-2023-23460CRITICAL9.8Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
CVE-2023-23459CRITICAL9.8Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now