2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-7304CRITICAL9.3Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface...
CVE-2023-49886CRITICAL9.8IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused ...
CVE-2023-21467CRITICAL9.8Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling ...
CVE-2023-7309CRITICAL10A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Da...
CVE-2023-41530CRITICAL9.8Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in a...
CVE-2023-41528CRITICAL9.8Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the tx...
CVE-2023-41527CRITICAL9.8Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in fun...
CVE-2023-41526CRITICAL9.8Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the user...
CVE-2023-41525CRITICAL9.8Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter ...
CVE-2023-53159CRITICAL9.1The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho...
CVE-2023-38036CRITICAL9.8A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to c...
CVE-2023-47030CRITICAL9.8An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa...
CVE-2023-47029CRITICAL9.8An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa...
CVE-2023-47031CRITICAL9.8An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to t...
CVE-2023-47295CRITICAL9.8A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injectin...
CVE-2023-47032CRITICAL9.8Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted ...
CVE-2023-48978CRITICAL9.8An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2023-47297CRITICAL9.8A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, inc...
CVE-2023-26226CRITICAL9.8A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
CVE-2023-41591CRITICAL9.8An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute...
CVE-2023-49641CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter ...
CVE-2023-31585CRITICAL9.8Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.
CVE-2023-42404CRITICAL9.8OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
CVE-2023-35817CRITICAL9.8DevExpress before 23.1.3 allows AsyncDownloader SSRF.
CVE-2023-35815CRITICAL9.8DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now