2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-24150CRITICAL9.8A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows...
CVE-2023-24149CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /e...
CVE-2023-24148CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in t...
CVE-2023-24146CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the...
CVE-2023-24145CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version paramete...
CVE-2023-24144CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the s...
CVE-2023-24143CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop param...
CVE-2023-24142CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize paramet...
CVE-2023-24141CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut para...
CVE-2023-24140CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum paramete...
CVE-2023-24139CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter i...
CVE-2023-24138CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in ...
CVE-2023-25139CRITICAL9.8sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct ...
CVE-2023-25135CRITICAL9.8vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques...
CVE-2023-0651CRITICAL9.8A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the c...
CVE-2023-0641CRITICAL9.1A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affe...
CVE-2023-0640CRITICAL9.8A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown fun...
CVE-2023-0638CRITICAL9.8A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects un...
CVE-2023-23076CRITICAL9.8OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
CVE-2023-22501CRITICAL9.1An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacke...
CVE-2023-24997CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In...
CVE-2023-0587CRITICAL9.1A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length heade...
CVE-2023-23928CRITICAL9.8reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This all...
CVE-2023-24241CRITICAL9.8Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/l...
CVE-2023-23924CRITICAL9.8Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now