2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36177CRITICAL9.8An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain se...
CVE-2023-31654CRITICAL9.8Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns...
CVE-2023-51210CRITICAL9.8SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id...
CVE-2023-48118CRITICAL9.8SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-51925CRITICAL9.8An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ...
CVE-2023-51924CRITICAL9.8An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows ...
CVE-2023-51906CRITICAL9.8An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the Servic...
CVE-2023-51928CRITICAL9.8An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ...
CVE-2023-51927CRITICAL9.8YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScri...
CVE-2023-51892CRITICAL9.8An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to th...
CVE-2023-50694CRITICAL9.8An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insuf...
CVE-2023-50693CRITICAL9.8An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.
CVE-2023-51947CRITICAL9.1Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and mod...
CVE-2023-50030CRITICAL9.8In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions ...
CVE-2023-50028CRITICAL9.8In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a gu...
CVE-2023-46351CRITICAL9.8In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManuf...
CVE-2023-43985CRITICAL9.8SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::pr...
CVE-2023-27168CRITICAL9.8An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code ...
CVE-2023-5716CRITICAL9.8ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary...
CVE-2023-40051CRITICAL9.9This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2....
CVE-2023-5806CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu...
CVE-2023-6816CRITICAL9.8A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical butt...
CVE-2023-44077CRITICAL9.8Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
CVE-2023-52042CRITICAL9.8An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary c...
CVE-2023-39691CRITICAL9.8An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET re...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now