2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7304 | CRITICAL | 9.3 | 3.7% | Oct 15, 2025 | Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface... |
| CVE-2023-49886 | CRITICAL | 9.8 | 0.6% | Oct 6, 2025 | IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused ... |
| CVE-2023-21467 | CRITICAL | 9.8 | 0.3% | Sep 3, 2025 | Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling ... |
| CVE-2023-7309 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Da... |
| CVE-2023-41530 | CRITICAL | 9.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in a... |
| CVE-2023-41528 | CRITICAL | 9.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the tx... |
| CVE-2023-41527 | CRITICAL | 9.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in fun... |
| CVE-2023-41526 | CRITICAL | 9.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the user... |
| CVE-2023-41525 | CRITICAL | 9.8 | 0.3% | Aug 7, 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter ... |
| CVE-2023-53159 | CRITICAL | 9.1 | 0.3% | Jul 28, 2025 | The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho... |
| CVE-2023-38036 | CRITICAL | 9.8 | 1.8% | Jul 12, 2025 | A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to c... |
| CVE-2023-47030 | CRITICAL | 9.8 | 0.6% | Jun 23, 2025 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa... |
| CVE-2023-47029 | CRITICAL | 9.8 | 0.6% | Jun 23, 2025 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa... |
| CVE-2023-47031 | CRITICAL | 9.8 | 0.6% | Jun 23, 2025 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to t... |
| CVE-2023-47295 | CRITICAL | 9.8 | 0.5% | Jun 23, 2025 | A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injectin... |
| CVE-2023-47032 | CRITICAL | 9.8 | 0.7% | Jun 23, 2025 | Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted ... |
| CVE-2023-48978 | CRITICAL | 9.8 | 0.9% | Jun 23, 2025 | An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted sc... |
| CVE-2023-47297 | CRITICAL | 9.8 | 0.5% | Jun 23, 2025 | A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, inc... |
| CVE-2023-26226 | CRITICAL | 9.8 | 0.3% | May 30, 2025 | A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682 |
| CVE-2023-41591 | CRITICAL | 9.8 | 0.3% | May 29, 2025 | An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute... |
| CVE-2023-49641 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter ... |
| CVE-2023-31585 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php. |
| CVE-2023-42404 | CRITICAL | 9.8 | 0.3% | Apr 28, 2025 | OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. |
| CVE-2023-35817 | CRITICAL | 9.8 | 0.3% | Apr 28, 2025 | DevExpress before 23.1.3 allows AsyncDownloader SSRF. |
| CVE-2023-35815 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now