2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-4472CRITICAL9.8Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled t...
CVE-2023-5841CRITICAL9.1Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy S...
CVE-2023-6078CRITICAL9.8An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Releas...
CVE-2023-6943CRITICAL9.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric ...
CVE-2023-51982CRITICAL9.8CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password a...
CVE-2023-51837CRITICAL9.8Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
CVE-2023-51840CRITICAL9.8DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
CVE-2023-51839CRITICAL9.1DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.
CVE-2023-52389CRITICAL9.8UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::U...
CVE-2023-38323CRITICAL9.8An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration...
CVE-2023-38319CRITICAL9.8An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allo...
CVE-2023-38318CRITICAL9.8An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file,...
CVE-2023-38317CRITICAL9.8An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configura...
CVE-2023-7227CRITICAL9.8 SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the ...
CVE-2023-6267CRITICAL9.8A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that...
CVE-2023-33759CRITICAL9.8SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to ...
CVE-2023-52040CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_412...
CVE-2023-52039CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415...
CVE-2023-52038CRITICAL9.8An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415...
CVE-2023-51889CRITICAL9.8Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute...
CVE-2023-51887CRITICAL9.8Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via craf...
CVE-2023-51885CRITICAL9.8Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the le...
CVE-2023-52221CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This ...
CVE-2023-35837CRITICAL9.8An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. Authentication for web interface is completed via an un...
CVE-2023-35835CRITICAL9.8An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial con...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now