2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46989HIGH7.8SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers...
CVE-2023-50445HIGH7.8Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 ...
CVE-2023-51010MEDIUM5.3An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL w...
CVE-2023-51006HIGH7.5An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified v...
CVE-2023-49230HIGH8.8An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows att...
CVE-2023-49229MEDIUM4.3An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web ser...
CVE-2023-49228MEDIUM6.4An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, wh...
CVE-2023-7124MEDIUM6.1A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unk...
CVE-2023-34829MEDIUM6.5Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
CVE-2023-7123CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracking System 1.0. This i...
CVE-2023-6879CRITICAL9.8Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av...
CVE-2023-49003MEDIUM5.3An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interac...
CVE-2023-49002HIGH7.5An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended acc...
CVE-2023-49001CRITICAL9.8An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via intera...
CVE-2023-49000CRITICAL9.8An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via i...
CVE-2023-46918MEDIUM4.6Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an...
CVE-2023-51084CRITICAL9.8hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.
CVE-2023-51080HIGH7.5The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
CVE-2023-51079MEDIUM5.3A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java c...
CVE-2023-51075HIGH7.5hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerabil...
CVE-2023-51074MEDIUM5.3json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
CVE-2023-47883CRITICAL9.8The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code ...
CVE-2023-47882HIGH7.1The Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to ...
CVE-2023-46919MEDIUM6.3Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) ...
CVE-2023-43955CRITICAL9.8The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. Thi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now