2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-52041CRITICAL9.8An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 ...
CVE-2023-49351CRITICAL9.8A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows atta...
CVE-2023-37523CRITICAL9.8Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker t...
CVE-2023-3211CRITICAL9.8The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter be...
CVE-2023-37522CRITICAL9.8HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker...
CVE-2023-0224CRITICAL9.8The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could...
CVE-2023-6395CRITICAL9.8The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling ...
CVE-2023-52106CRITICAL9.1Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of...
CVE-2023-52103CRITICAL9.8Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds r...
CVE-2023-52101CRITICAL9.1Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service a...
CVE-2023-22527CRITICAL9.8A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta...
CVE-2023-6623CRITICAL9.8The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local var...
CVE-2023-6049CRITICAL9.8The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which coul...
CVE-2023-50729CRITICAL9.8Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnera...
CVE-2023-46226CRITICAL9.8Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users ar...
CVE-2023-46943CRITICAL9.1An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generati...
CVE-2023-31030CRITICAL9.8NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack...
CVE-2023-31029CRITICAL9.8NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthen...
CVE-2023-31024CRITICAL9.8NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack m...
CVE-2023-28897CRITICAL9.8The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulner...
CVE-2023-49262CRITICAL9.8The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided the...
CVE-2023-49255CRITICAL9.8The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order...
CVE-2023-49253CRITICAL9.8Root user password is hardcoded into the device and cannot be changed in the user interface.
CVE-2023-7028CRITICAL9.8An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16....
CVE-2023-52026CRITICAL9.8TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now