2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4472 | CRITICAL | 9.8 | 0.6% | Feb 1, 2024 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled t... |
| CVE-2023-5841 | CRITICAL | 9.1 | 1.3% | Feb 1, 2024 | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy S... |
| CVE-2023-6078 | CRITICAL | 9.8 | 1.6% | Feb 1, 2024 | An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Releas... |
| CVE-2023-6943 | CRITICAL | 9.8 | 1.8% | Jan 30, 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric ... |
| CVE-2023-51982 | CRITICAL | 9.8 | 0.7% | Jan 30, 2024 | CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password a... |
| CVE-2023-51837 | CRITICAL | 9.8 | 0.5% | Jan 30, 2024 | Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. |
| CVE-2023-51840 | CRITICAL | 9.8 | 0.6% | Jan 29, 2024 | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. |
| CVE-2023-51839 | CRITICAL | 9.1 | 0.4% | Jan 29, 2024 | DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm. |
| CVE-2023-52389 | CRITICAL | 9.8 | 0.9% | Jan 27, 2024 | UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::U... |
| CVE-2023-38323 | CRITICAL | 9.8 | 1.1% | Jan 26, 2024 | An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration... |
| CVE-2023-38319 | CRITICAL | 9.8 | 1.1% | Jan 26, 2024 | An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allo... |
| CVE-2023-38318 | CRITICAL | 9.8 | 1.1% | Jan 26, 2024 | An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file,... |
| CVE-2023-38317 | CRITICAL | 9.8 | 1.1% | Jan 26, 2024 | An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configura... |
| CVE-2023-7227 | CRITICAL | 9.8 | 1.3% | Jan 25, 2024 | SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the ... |
| CVE-2023-6267 | CRITICAL | 9.8 | 0.7% | Jan 25, 2024 | A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that... |
| CVE-2023-33759 | CRITICAL | 9.8 | 0.8% | Jan 25, 2024 | SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to ... |
| CVE-2023-52040 | CRITICAL | 9.8 | 0.9% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_412... |
| CVE-2023-52039 | CRITICAL | 9.8 | 0.8% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415... |
| CVE-2023-52038 | CRITICAL | 9.8 | 0.8% | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415... |
| CVE-2023-51889 | CRITICAL | 9.8 | 1.3% | Jan 24, 2024 | Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute... |
| CVE-2023-51887 | CRITICAL | 9.8 | 2.5% | Jan 24, 2024 | Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via craf... |
| CVE-2023-51885 | CRITICAL | 9.8 | 1.3% | Jan 24, 2024 | Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the le... |
| CVE-2023-52221 | CRITICAL | 9.8 | 0.6% | Jan 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This ... |
| CVE-2023-35837 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. Authentication for web interface is completed via an un... |
| CVE-2023-35835 | CRITICAL | 9.8 | 0.5% | Jan 23, 2024 | An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial con... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now