2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24163 | CRITICAL | 9.8 | 1.4% | Jan 31, 2023 | SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator tem... |
| CVE-2023-24162 | CRITICAL | 9.8 | 1.3% | Jan 31, 2023 | Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readOb... |
| CVE-2023-22900 | CRITICAL | 9.8 | 1.0% | Jan 31, 2023 | Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vu... |
| CVE-2023-23582 | CRITICAL | 9.8 | 0.8% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could a... |
| CVE-2023-24020 | CRITICAL | 9.8 | 0.6% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple at... |
| CVE-2023-24612 | CRITICAL | 9.8 | 1.3% | Jan 30, 2023 | The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option. |
| CVE-2023-0570 | CRITICAL | 9.8 | 0.6% | Jan 29, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System ... |
| CVE-2023-0562 | CRITICAL | 9.8 | 41.2% | Jan 28, 2023 | A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by th... |
| CVE-2023-0558 | CRITICAL | 9.8 | 0.9% | Jan 27, 2023 | The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susc... |
| CVE-2023-0530 | CRITICAL | 9.8 | 0.6% | Jan 27, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical.... |
| CVE-2023-24508 | CRITICAL | 9.6 | 1.6% | Jan 26, 2023 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vu... |
| CVE-2023-24456 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login. |
| CVE-2023-24444 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login. |
| CVE-2023-24443 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2023-24441 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2023-24430 | CRITICAL | 9.8 | 1.3% | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2023-24429 | CRITICAL | 9.8 | 1.3% | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents... |
| CVE-2023-24427 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. |
| CVE-2023-24170 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat. |
| CVE-2023-24169 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c. |
| CVE-2023-24167 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node. |
| CVE-2023-24166 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet. |
| CVE-2023-24165 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo. |
| CVE-2023-24164 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318. |
| CVE-2023-24022 | CRITICAL | 9.8 | 1.6% | Jan 26, 2023 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now