2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-24163CRITICAL9.8SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator tem...
CVE-2023-24162CRITICAL9.8Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readOb...
CVE-2023-22900CRITICAL9.8Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vu...
CVE-2023-23582CRITICAL9.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could a...
CVE-2023-24020CRITICAL9.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple at...
CVE-2023-24612CRITICAL9.8The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.
CVE-2023-0570CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System ...
CVE-2023-0562CRITICAL9.8A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by th...
CVE-2023-0558CRITICAL9.8The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susc...
CVE-2023-0530CRITICAL9.8A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical....
CVE-2023-24508CRITICAL9.6Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vu...
CVE-2023-24456CRITICAL9.8Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
CVE-2023-24444CRITICAL9.8Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
CVE-2023-24443CRITICAL9.8Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2023-24441CRITICAL9.8Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2023-24430CRITICAL9.8Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2023-24429CRITICAL9.8Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents...
CVE-2023-24427CRITICAL9.8Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
CVE-2023-24170CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
CVE-2023-24169CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
CVE-2023-24167CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
CVE-2023-24166CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
CVE-2023-24165CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
CVE-2023-24164CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
CVE-2023-24022CRITICAL9.8Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now