2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48392 | CRITICAL | 9.8 | 0.6% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un... |
| CVE-2023-48390 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerabi... |
| CVE-2023-48388 | CRITICAL | 9.8 | 0.9% | Dec 15, 2023 | Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerab... |
| CVE-2023-48384 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. A... |
| CVE-2023-46279 | CRITICAL | 9.8 | 1.7% | Dec 15, 2023 | Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are r... |
| CVE-2023-29234 | CRITICAL | 9.8 | 7.4% | Dec 15, 2023 | A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 thro... |
| CVE-2023-48376 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file... |
| CVE-2023-48372 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attack... |
| CVE-2023-48371 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated r... |
| CVE-2023-48050 | CRITICAL | 9.8 | 0.8% | Dec 15, 2023 | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka ... |
| CVE-2023-40954 | CRITICAL | 9.8 | 0.9% | Dec 15, 2023 | A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12... |
| CVE-2023-48049 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through... |
| CVE-2023-4489 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP G... |
| CVE-2023-45894 | CRITICAL | 10 | 1.2% | Dec 14, 2023 | The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the serv... |
| CVE-2023-47261 | CRITICAL | 9.8 | 1.5% | Dec 14, 2023 | Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/getting... |
| CVE-2023-50563 | CRITICAL | 9.8 | 0.6% | Dec 14, 2023 | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. |
| CVE-2023-50073 | CRITICAL | 9.8 | 0.6% | Dec 14, 2023 | EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. |
| CVE-2023-46141 | CRITICAL | 9.8 | 0.9% | Dec 14, 2023 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic ... |
| CVE-2023-0757 | CRITICAL | 9.8 | 0.9% | Dec 14, 2023 | Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProCon... |
| CVE-2023-49708 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in Starshop component for Joomla. |
| CVE-2023-49707 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in S5 Register module for Joomla. |
| CVE-2023-48925 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and o... |
| CVE-2023-46348 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain ... |
| CVE-2023-40630 | CRITICAL | 9.8 | 0.7% | Dec 14, 2023 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. |
| CVE-2023-40629 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in LMS Lite component for Joomla. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now