2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36177 | CRITICAL | 9.8 | 28.9% | Jan 23, 2024 | An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain se... |
| CVE-2023-31654 | CRITICAL | 9.8 | 0.6% | Jan 23, 2024 | Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns... |
| CVE-2023-51210 | CRITICAL | 9.8 | 1.1% | Jan 23, 2024 | SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id... |
| CVE-2023-48118 | CRITICAL | 9.8 | 1.2% | Jan 22, 2024 | SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-51925 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ... |
| CVE-2023-51924 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows ... |
| CVE-2023-51906 | CRITICAL | 9.8 | 1.2% | Jan 20, 2024 | An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the Servic... |
| CVE-2023-51928 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ... |
| CVE-2023-51927 | CRITICAL | 9.8 | 0.6% | Jan 20, 2024 | YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScri... |
| CVE-2023-51892 | CRITICAL | 9.8 | 1.2% | Jan 20, 2024 | An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to th... |
| CVE-2023-50694 | CRITICAL | 9.8 | 1.0% | Jan 19, 2024 | An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insuf... |
| CVE-2023-50693 | CRITICAL | 9.8 | 1.0% | Jan 19, 2024 | An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request. |
| CVE-2023-51947 | CRITICAL | 9.1 | 0.9% | Jan 19, 2024 | Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and mod... |
| CVE-2023-50030 | CRITICAL | 9.8 | 0.7% | Jan 19, 2024 | In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions ... |
| CVE-2023-50028 | CRITICAL | 9.8 | 0.7% | Jan 19, 2024 | In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a gu... |
| CVE-2023-46351 | CRITICAL | 9.8 | 0.5% | Jan 19, 2024 | In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManuf... |
| CVE-2023-43985 | CRITICAL | 9.8 | 0.5% | Jan 19, 2024 | SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::pr... |
| CVE-2023-27168 | CRITICAL | 9.8 | 1.1% | Jan 19, 2024 | An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code ... |
| CVE-2023-5716 | CRITICAL | 9.8 | 0.6% | Jan 19, 2024 | ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary... |
| CVE-2023-40051 | CRITICAL | 9.9 | 0.6% | Jan 18, 2024 | This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.... |
| CVE-2023-5806 | CRITICAL | 9.8 | 0.5% | Jan 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu... |
| CVE-2023-6816 | CRITICAL | 9.8 | 2.1% | Jan 18, 2024 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical butt... |
| CVE-2023-44077 | CRITICAL | 9.8 | 0.4% | Jan 17, 2024 | Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636. |
| CVE-2023-52042 | CRITICAL | 9.8 | 0.9% | Jan 16, 2024 | An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary c... |
| CVE-2023-39691 | CRITICAL | 9.8 | 0.6% | Jan 16, 2024 | An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET re... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now