2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-53926CRITICAL9.8PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers ...
CVE-2023-53923CRITICAL9.8UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrati...
CVE-2023-53922CRITICAL9.8TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthe...
CVE-2023-53921CRITICAL9.8SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to...
CVE-2023-53914CRITICAL9.8UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user...
CVE-2023-53899CRITICAL9.8PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in...
CVE-2023-53895CRITICAL9.8PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts...
CVE-2023-53894CRITICAL9.8phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type com...
CVE-2023-53877CRITICAL9.8Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to ma...
CVE-2023-53874CRITICAL9.8GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows att...
CVE-2023-53872CRITICAL9.3Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execu...
CVE-2023-53871CRITICAL9.8Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PH...
CVE-2023-53740CRITICAL9.8Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password ...
CVE-2023-53774CRITICAL9.8MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to se...
CVE-2023-53771CRITICAL9.8MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root passwor...
CVE-2023-53739CRITICAL9.9Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers t...
CVE-2023-53794CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: cifs: fix session state check in reconnect to avoid...
CVE-2023-53769CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The en...
CVE-2023-53751CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Serv...
CVE-2023-7330CRITICAL9.3Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php....
CVE-2023-7325CRITICAL9.3Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request fo...
CVE-2023-28815CRITICAL9.8Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command in...
CVE-2023-28814CRITICAL9.8Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the impro...
CVE-2023-7311CRITICAL9.3BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoi...
CVE-2023-7305CRITICAL9.2SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Und...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now