2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49569 | CRITICAL | 9.8 | 1.5% | Jan 12, 2024 | A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker t... |
| CVE-2023-30016 | CRITICAL | 9.8 | 1.0% | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co... |
| CVE-2023-30015 | CRITICAL | 9.8 | 1.0% | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co... |
| CVE-2023-30014 | CRITICAL | 9.8 | 1.0% | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co... |
| CVE-2023-50919 | CRITICAL | 9.8 | 47.8% | Jan 12, 2024 | An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string ... |
| CVE-2023-37117 | CRITICAL | 9.8 | 0.9% | Jan 12, 2024 | A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP. |
| CVE-2023-51350 | CRITICAL | 9.8 | 1.3% | Jan 11, 2024 | A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code v... |
| CVE-2023-51987 | CRITICAL | 9.8 | 0.9% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator... |
| CVE-2023-51984 | CRITICAL | 9.8 | 2.0% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attack... |
| CVE-2023-6875 | CRITICAL | 9.8 | 90.3% | Jan 11, 2024 | The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i... |
| CVE-2023-6634 | CRITICAL | 9.8 | 8.5% | Jan 11, 2024 | The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via... |
| CVE-2023-6316 | CRITICAL | 9.8 | 1.4% | Jan 11, 2024 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in ... |
| CVE-2023-6220 | CRITICAL | 9.8 | 1.4% | Jan 11, 2024 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ... |
| CVE-2023-52032 | CRITICAL | 9.8 | 1.6% | Jan 11, 2024 | TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via th... |
| CVE-2023-52031 | CRITICAL | 9.8 | 1.5% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52030 | CRITICAL | 9.8 | 1.5% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52029 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52028 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52027 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-51123 | CRITICAL | 9.8 | 24.4% | Jan 10, 2024 | An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted PO... |
| CVE-2023-40414 | CRITICAL | 9.8 | 1.0% | Jan 10, 2024 | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPad... |
| CVE-2023-52064 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyf... |
| CVE-2023-51126 | CRITICAL | 9.8 | 31.1% | Jan 10, 2024 | Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands... |
| CVE-2023-31488 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appli... |
| CVE-2023-51970 | CRITICAL | 9.8 | 0.7% | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now