2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-49665CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' paramete...
CVE-2023-49658CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parame...
CVE-2023-49639CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' pa...
CVE-2023-49633CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' param...
CVE-2023-49625CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the...
CVE-2023-49624CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter ...
CVE-2023-49622CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' paramete...
CVE-2023-49442CRITICAL9.8Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary ...
CVE-2023-50090CRITICAL9.8Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write a...
CVE-2023-46741CRITICAL9.8CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 th...
CVE-2023-46740CRITICAL9.8CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string...
CVE-2023-39655CRITICAL9.6A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a spe...
CVE-2023-51784CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLon...
CVE-2023-52314CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbi...
CVE-2023-52311CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary c...
CVE-2023-52310CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute a...
CVE-2023-52309CRITICAL9.8Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service...
CVE-2023-52307CRITICAL9.8Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or ev...
CVE-2023-52304CRITICAL9.8Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even m...
CVE-2023-50921CRITICAL9.8An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system modu...
CVE-2023-46308CRITICAL9.8In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nested...
CVE-2023-45724CRITICAL9.8HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the ...
CVE-2023-45723CRITICAL9.8HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoint...
CVE-2023-45722CRITICAL9.8HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to ...
CVE-2023-50351CRITICAL9.1HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compro...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now