2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22807 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal ... |
| CVE-2023-22804 | CRITICAL | 9.8 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This cou... |
| CVE-2023-0102 | CRITICAL | 9.1 | 0.7% | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could... |
| CVE-2023-25156 | CRITICAL | 9.8 | 0.9% | Feb 15, 2023 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e... |
| CVE-2023-25765 | CRITICAL | 9.9 | 1.1% | Feb 15, 2023 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Securit... |
| CVE-2023-21803 | CRITICAL | 9.8 | 1.8% | Feb 14, 2023 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability |
| CVE-2023-21716 | CRITICAL | 9.8 | 82.3% | Feb 14, 2023 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2023-21692 | CRITICAL | 9.8 | 21.2% | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
| CVE-2023-21690 | CRITICAL | 9.8 | 27.5% | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
| CVE-2023-21689 | CRITICAL | 9.8 | 26.5% | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
| CVE-2023-25725 | CRITICAL | 9.1 | 5.5% | Feb 14, 2023 | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situatio... |
| CVE-2023-24161 | CRITICAL | 9.8 | 1.9% | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in... |
| CVE-2023-24160 | CRITICAL | 9.8 | 1.9% | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in th... |
| CVE-2023-24159 | CRITICAL | 9.8 | 1.9% | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in th... |
| CVE-2023-24482 | CRITICAL | 9.8 | 0.8% | Feb 14, 2023 | A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS ... |
| CVE-2023-24530 | CRITICAL | 9.1 | 0.6% | Feb 14, 2023 | SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to uplo... |
| CVE-2023-24646 | CRITICAL | 9.8 | 1.1% | Feb 13, 2023 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attacker... |
| CVE-2023-24084 | CRITICAL | 9.8 | 0.9% | Feb 13, 2023 | ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. |
| CVE-2023-25718 | CRITICAL | 9.8 | 0.7% | Feb 13, 2023 | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio... |
| CVE-2023-25717 | CRITICAL | 9.8 | 95.1% | Feb 13, 2023 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated... |
| CVE-2023-24188 | CRITICAL | 9.1 | 1.5% | Feb 13, 2023 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for ... |
| CVE-2023-23551 | CRITICAL | 9.8 | 0.9% | Feb 13, 2023 | Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to ... |
| CVE-2023-0789 | CRITICAL | 9.8 | 1.7% | Feb 12, 2023 | Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0788 | CRITICAL | 9.8 | 0.9% | Feb 12, 2023 | Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0784 | CRITICAL | 9.8 | 0.8% | Feb 12, 2023 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unkn... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now