2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52041 | CRITICAL | 9.8 | 0.9% | Jan 16, 2024 | An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 ... |
| CVE-2023-49351 | CRITICAL | 9.8 | 0.6% | Jan 16, 2024 | A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows atta... |
| CVE-2023-37523 | CRITICAL | 9.8 | 0.4% | Jan 16, 2024 | Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker t... |
| CVE-2023-3211 | CRITICAL | 9.8 | 0.8% | Jan 16, 2024 | The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter be... |
| CVE-2023-37522 | CRITICAL | 9.8 | 0.4% | Jan 16, 2024 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker... |
| CVE-2023-0224 | CRITICAL | 9.8 | 3.7% | Jan 16, 2024 | The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could... |
| CVE-2023-6395 | CRITICAL | 9.8 | 1.6% | Jan 16, 2024 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling ... |
| CVE-2023-52106 | CRITICAL | 9.1 | 0.3% | Jan 16, 2024 | Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of... |
| CVE-2023-52103 | CRITICAL | 9.8 | 0.5% | Jan 16, 2024 | Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds r... |
| CVE-2023-52101 | CRITICAL | 9.1 | 0.4% | Jan 16, 2024 | Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service a... |
| CVE-2023-22527 | CRITICAL | 9.8 | 100.0% | Jan 16, 2024 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta... |
| CVE-2023-6623 | CRITICAL | 9.8 | 50.7% | Jan 15, 2024 | The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local var... |
| CVE-2023-6049 | CRITICAL | 9.8 | 0.9% | Jan 15, 2024 | The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which coul... |
| CVE-2023-50729 | CRITICAL | 9.8 | 0.6% | Jan 15, 2024 | Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnera... |
| CVE-2023-46226 | CRITICAL | 9.8 | 1.9% | Jan 15, 2024 | Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users ar... |
| CVE-2023-46943 | CRITICAL | 9.1 | 0.5% | Jan 13, 2024 | An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generati... |
| CVE-2023-31030 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack... |
| CVE-2023-31029 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthen... |
| CVE-2023-31024 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack m... |
| CVE-2023-28897 | CRITICAL | 9.8 | 0.3% | Jan 12, 2024 | The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulner... |
| CVE-2023-49262 | CRITICAL | 9.8 | 0.7% | Jan 12, 2024 | The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided the... |
| CVE-2023-49255 | CRITICAL | 9.8 | 0.7% | Jan 12, 2024 | The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order... |
| CVE-2023-49253 | CRITICAL | 9.8 | 0.6% | Jan 12, 2024 | Root user password is hardcoded into the device and cannot be changed in the user interface. |
| CVE-2023-7028 | CRITICAL | 9.8 | 95.0% | Jan 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.... |
| CVE-2023-52026 | CRITICAL | 9.8 | 1.6% | Jan 12, 2024 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now