2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-22807CRITICAL9.8LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal ...
CVE-2023-22804CRITICAL9.8LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This cou...
CVE-2023-0102CRITICAL9.1LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could...
CVE-2023-25156CRITICAL9.8Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e...
CVE-2023-25765CRITICAL9.9In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Securit...
CVE-2023-21803CRITICAL9.8Windows iSCSI Discovery Service Remote Code Execution Vulnerability
CVE-2023-21716CRITICAL9.8Microsoft Word Remote Code Execution Vulnerability
CVE-2023-21692CRITICAL9.8Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
CVE-2023-21690CRITICAL9.8Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
CVE-2023-21689CRITICAL9.8Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
CVE-2023-25725CRITICAL9.1HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situatio...
CVE-2023-24161CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in...
CVE-2023-24160CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in th...
CVE-2023-24159CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in th...
CVE-2023-24482CRITICAL9.8A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS ...
CVE-2023-24530CRITICAL9.1SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to uplo...
CVE-2023-24646CRITICAL9.8An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attacker...
CVE-2023-24084CRITICAL9.8ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
CVE-2023-25718CRITICAL9.8In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio...
CVE-2023-25717CRITICAL9.8Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated...
CVE-2023-24188CRITICAL9.1ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for ...
CVE-2023-23551CRITICAL9.8 Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to ...
CVE-2023-0789CRITICAL9.8Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0788CRITICAL9.8Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0784CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unkn...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now