2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51392 | CRITICAL | 9.8 | 0.2% | Feb 23, 2024 | Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, po... |
| CVE-2023-51653 | CRITICAL | 9.8 | 2.1% | Feb 22, 2024 | Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect... |
| CVE-2023-51389 | CRITICAL | 9.8 | 1.3% | Feb 22, 2024 | Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse ym... |
| CVE-2023-51388 | CRITICAL | 9.8 | 1.3% | Feb 22, 2024 | Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the... |
| CVE-2023-52153 | CRITICAL | 9.8 | 0.8% | Feb 21, 2024 | A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthen... |
| CVE-2023-51828 | CRITICAL | 9.8 | 0.9% | Feb 21, 2024 | A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthe... |
| CVE-2023-37177 | CRITICAL | 9.8 | 1.1% | Feb 21, 2024 | SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute a... |
| CVE-2023-24331 | CRITICAL | 9.8 | 2.1% | Feb 21, 2024 | Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run ar... |
| CVE-2023-6936 | CRITICAL | 9.1 | 0.6% | Feb 20, 2024 | In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS clie... |
| CVE-2023-45318 | CRITICAL | 9.8 | 1.7% | Feb 20, 2024 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit... |
| CVE-2023-38562 | CRITICAL | 9.1 | 1.1% | Feb 20, 2024 | A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01... |
| CVE-2023-49109 | CRITICAL | 9.8 | 2.3% | Feb 20, 2024 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1.... |
| CVE-2023-6249 | CRITICAL | 9.8 | 0.4% | Feb 18, 2024 | Signed to unsigned conversion esp32_ipm_send |
| CVE-2023-5779 | CRITICAL | 9.8 | 0.4% | Feb 18, 2024 | can: out of bounds in remove_rx_filter function |
| CVE-2023-6749 | CRITICAL | 9.8 | 0.4% | Feb 18, 2024 | Unchecked length coming from user input in settings shell |
| CVE-2023-52381 | CRITICAL | 9.8 | 0.4% | Feb 18, 2024 | Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service conf... |
| CVE-2023-52378 | CRITICAL | 9.8 | 0.5% | Feb 18, 2024 | Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerabili... |
| CVE-2023-52370 | CRITICAL | 9.8 | 0.5% | Feb 18, 2024 | Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause ... |
| CVE-2023-52369 | CRITICAL | 9.1 | 0.4% | Feb 18, 2024 | Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availabi... |
| CVE-2023-40057 | CRITICAL | 9 | 4.2% | Feb 15, 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited,... |
| CVE-2023-7081 | CRITICAL | 9.8 | 0.5% | Feb 15, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online P... |
| CVE-2023-5155 | CRITICAL | 9.8 | 0.5% | Feb 15, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information... |
| CVE-2023-39245 | CRITICAL | 9.8 | 0.4% | Feb 15, 2024 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability i... |
| CVE-2023-39244 | CRITICAL | 9.8 | 0.5% | Feb 15, 2024 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in... |
| CVE-2023-32484 | CRITICAL | 9.8 | 0.6% | Feb 15, 2024 | Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input val... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now