2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0321 | CRITICAL | 9.1 | 0.9% | Jan 26, 2023 | Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration fil... |
| CVE-2023-23331 | CRITICAL | 9.8 | 0.9% | Jan 24, 2023 | Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection. |
| CVE-2023-23560 | CRITICAL | 9.8 | 15.0% | Jan 23, 2023 | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. |
| CVE-2023-0435 | CRITICAL | 9.8 | 0.7% | Jan 22, 2023 | Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. |
| CVE-2023-22884 | CRITICAL | 9.8 | 11.1% | Jan 21, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou... |
| CVE-2023-24028 | CRITICAL | 9.8 | 0.7% | Jan 20, 2023 | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function... |
| CVE-2023-23607 | CRITICAL | 9.8 | 1.6% | Jan 20, 2023 | erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauth... |
| CVE-2023-23489 | CRITICAL | 9.8 | 11.2% | Jan 20, 2023 | The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection... |
| CVE-2023-23488 | CRITICAL | 9.8 | 92.5% | Jan 20, 2023 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit... |
| CVE-2023-22964 | CRITICAL | 9.1 | 2.4% | Jan 20, 2023 | Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when L... |
| CVE-2023-20025 | CRITICAL | 9.8 | 1.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co... |
| CVE-2023-22741 | CRITICAL | 9.8 | 2.4% | Jan 19, 2023 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions ... |
| CVE-2023-21890 | CRITICAL | 9.8 | 0.8% | Jan 18, 2023 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Cor... |
| CVE-2023-22732 | CRITICAL | 9.8 | 0.7% | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio... |
| CVE-2023-22727 | CRITICAL | 9.8 | 0.9% | Jan 17, 2023 | CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\D... |
| CVE-2023-22357 | CRITICAL | 9.8 | 1.2% | Jan 17, 2023 | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS ... |
| CVE-2023-22303 | CRITICAL | 9.8 | 0.9% | Jan 17, 2023 | TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerabil... |
| CVE-2023-22279 | CRITICAL | 9.8 | 1.1% | Jan 17, 2023 | MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an... |
| CVE-2023-0332 | CRITICAL | 9.8 | 0.9% | Jan 17, 2023 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affecte... |
| CVE-2023-0324 | CRITICAL | 9.8 | 18.8% | Jan 16, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Aff... |
| CVE-2023-0311 | CRITICAL | 9.8 | 0.9% | Jan 15, 2023 | Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10. |
| CVE-2023-0307 | CRITICAL | 9.8 | 0.6% | Jan 15, 2023 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10. |
| CVE-2023-0299 | CRITICAL | 9.8 | 0.9% | Jan 14, 2023 | Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. |
| CVE-2023-0297 | CRITICAL | 9.8 | 97.0% | Jan 14, 2023 | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. |
| CVE-2023-22497 | CRITICAL | 9.1 | 0.7% | Jan 14, 2023 | Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now