2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-6339CRITICAL9.8Google Nest WiFi Pro root code-execution & user-data compromise
CVE-2023-47458CRITICAL9.8An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions c...
CVE-2023-50711CRITICAL9.8vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starti...
CVE-2023-48419CRITICAL9.8An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
CVE-2023-4280CRITICAL9.8An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker ...
CVE-2023-6436CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics W...
CVE-2023-33025CRITICAL9.8Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
CVE-2023-32874CRITICAL9.8In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote cod...
CVE-2023-5877CRITICAL9.8The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliat...
CVE-2023-51469CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Chec...
CVE-2023-51423CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team W...
CVE-2023-52181CRITICAL9.8Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a ...
CVE-2023-52262CRITICAL9.8outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code b...
CVE-2023-50651CRITICAL9.8TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-50589CRITICAL9.8Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter ...
CVE-2023-51136CRITICAL9.8TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSched...
CVE-2023-51135CRITICAL9.8TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSet...
CVE-2023-51133CRITICAL9.8TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute.
CVE-2023-50578CRITICAL9.8Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/...
CVE-2023-7175CRITICAL9.8A vulnerability was found in Campcodes Online College Library System 1.0. It has been rated as critical. Affected by thi...
CVE-2023-52252CRITICAL9.8Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow...
CVE-2023-41544CRITICAL9.8SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted ...
CVE-2023-41543CRITICAL9.8SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive in...
CVE-2023-41542CRITICAL9.8SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensi...
CVE-2023-50035CRITICAL9.8PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is dire...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now