2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-0321CRITICAL9.1Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration fil...
CVE-2023-23331CRITICAL9.8Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
CVE-2023-23560CRITICAL9.8In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
CVE-2023-0435CRITICAL9.8Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.
CVE-2023-22884CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou...
CVE-2023-24028CRITICAL9.8In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function...
CVE-2023-23607CRITICAL9.8erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauth...
CVE-2023-23489CRITICAL9.8The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection...
CVE-2023-23488CRITICAL9.8The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit...
CVE-2023-22964CRITICAL9.1Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when L...
CVE-2023-20025CRITICAL9.8A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co...
CVE-2023-22741CRITICAL9.8Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions ...
CVE-2023-21890CRITICAL9.8Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Cor...
CVE-2023-22732CRITICAL9.8Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio...
CVE-2023-22727CRITICAL9.8CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\D...
CVE-2023-22357CRITICAL9.8Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS ...
CVE-2023-22303CRITICAL9.8TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerabil...
CVE-2023-22279CRITICAL9.8MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an...
CVE-2023-0332CRITICAL9.8A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affecte...
CVE-2023-0324CRITICAL9.8A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Aff...
CVE-2023-0311CRITICAL9.8Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
CVE-2023-0307CRITICAL9.8Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
CVE-2023-0299CRITICAL9.8Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
CVE-2023-0297CRITICAL9.8Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
CVE-2023-22497CRITICAL9.1Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now