2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49256HIGH7.5It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded...
CVE-2023-49255CRITICAL9.8The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order...
CVE-2023-49254HIGH8.8Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destinati...
CVE-2023-49253CRITICAL9.8Root user password is hardcoded into the device and cannot be changed in the user interface.
CVE-2023-7028CRITICAL9.8An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16....
CVE-2023-6955MEDIUM5.3A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, ...
CVE-2023-5356HIGH8.8Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting...
CVE-2023-4812MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting...
CVE-2023-2030MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and...
CVE-2023-0437HIGH7.5When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an i...
CVE-2023-52026CRITICAL9.8TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via th...
CVE-2023-51806MEDIUM5.4File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
CVE-2023-51790MEDIUM6.1Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the l...
CVE-2023-49569CRITICAL9.8A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker t...
CVE-2023-49568HIGH7.5A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an a...
CVE-2023-48909HIGH8.8An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.
CVE-2023-30016CRITICAL9.8SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co...
CVE-2023-30015CRITICAL9.8SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co...
CVE-2023-30014CRITICAL9.8SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary co...
CVE-2023-6740HIGH7.8Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user t...
CVE-2023-6735HIGH7.8Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escal...
CVE-2023-50920MEDIUM5.5An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot,...
CVE-2023-50919CRITICAL9.8An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string ...
CVE-2023-40362MEDIUM4.3An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protectio...
CVE-2023-31211MEDIUM6.5Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credent...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now