2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6339 | CRITICAL | 9.8 | 0.2% | Jan 2, 2024 | Google Nest WiFi Pro root code-execution & user-data compromise |
| CVE-2023-47458 | CRITICAL | 9.8 | 0.8% | Jan 2, 2024 | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions c... |
| CVE-2023-50711 | CRITICAL | 9.8 | 0.7% | Jan 2, 2024 | vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starti... |
| CVE-2023-48419 | CRITICAL | 9.8 | 0.2% | Jan 2, 2024 | An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege |
| CVE-2023-4280 | CRITICAL | 9.8 | 0.4% | Jan 2, 2024 | An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker ... |
| CVE-2023-6436 | CRITICAL | 9.8 | 0.5% | Jan 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics W... |
| CVE-2023-33025 | CRITICAL | 9.8 | 0.4% | Jan 2, 2024 | Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call. |
| CVE-2023-32874 | CRITICAL | 9.8 | 1.0% | Jan 2, 2024 | In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote cod... |
| CVE-2023-5877 | CRITICAL | 9.8 | 0.9% | Jan 1, 2024 | The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliat... |
| CVE-2023-51469 | CRITICAL | 9.8 | 0.6% | Dec 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Chec... |
| CVE-2023-51423 | CRITICAL | 9.8 | 0.6% | Dec 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team W... |
| CVE-2023-52181 | CRITICAL | 9.8 | 0.6% | Dec 31, 2023 | Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a ... |
| CVE-2023-52262 | CRITICAL | 9.8 | 0.9% | Dec 30, 2023 | outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code b... |
| CVE-2023-50651 | CRITICAL | 9.8 | 1.7% | Dec 30, 2023 | TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-50589 | CRITICAL | 9.8 | 0.7% | Dec 30, 2023 | Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter ... |
| CVE-2023-51136 | CRITICAL | 9.8 | 0.6% | Dec 30, 2023 | TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSched... |
| CVE-2023-51135 | CRITICAL | 9.8 | 0.6% | Dec 30, 2023 | TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSet... |
| CVE-2023-51133 | CRITICAL | 9.8 | 0.6% | Dec 30, 2023 | TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute. |
| CVE-2023-50578 | CRITICAL | 9.8 | 2.2% | Dec 30, 2023 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/... |
| CVE-2023-7175 | CRITICAL | 9.8 | 0.6% | Dec 30, 2023 | A vulnerability was found in Campcodes Online College Library System 1.0. It has been rated as critical. Affected by thi... |
| CVE-2023-52252 | CRITICAL | 9.8 | 1.1% | Dec 30, 2023 | Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow... |
| CVE-2023-41544 | CRITICAL | 9.8 | 2.7% | Dec 30, 2023 | SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted ... |
| CVE-2023-41543 | CRITICAL | 9.8 | 0.9% | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive in... |
| CVE-2023-41542 | CRITICAL | 9.8 | 0.9% | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensi... |
| CVE-2023-50035 | CRITICAL | 9.8 | 0.6% | Dec 29, 2023 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is dire... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now