2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25235 | HIGH | 7.5 | 11.1% | Feb 27, 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid. |
| CVE-2023-24656 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subj... |
| CVE-2023-24654 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name... |
| CVE-2023-24653 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldp... |
| CVE-2023-24652 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Desc... |
| CVE-2023-24364 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the user... |
| CVE-2023-1070 | HIGH | 7.1 | 0.8% | Feb 27, 2023 | External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. |
| CVE-2023-0487 | HIGH | 7.2 | 1.5% | Feb 27, 2023 | The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it i... |
| CVE-2023-0381 | HIGH | 8.8 | 1.3% | Feb 27, 2023 | The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using ... |
| CVE-2023-0331 | HIGH | 7.5 | 0.8% | Feb 27, 2023 | The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when gen... |
| CVE-2023-0279 | HIGH | 7.2 | 0.8% | Feb 27, 2023 | The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using ... |
| CVE-2023-0278 | HIGH | 7.2 | 0.8% | Feb 27, 2023 | The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2023-23109 | HIGH | 7.5 | 0.7% | Feb 27, 2023 | In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a divide by... |
| CVE-2023-23108 | HIGH | 7.5 | 0.9% | Feb 27, 2023 | In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL poin... |
| CVE-2023-1063 | HIGH | 8.8 | 0.7% | Feb 27, 2023 | A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by ... |
| CVE-2023-1062 | HIGH | 8.8 | 0.7% | Feb 27, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Doctors Appointment System 1.0. Affected ... |
| CVE-2023-1061 | HIGH | 8.8 | 0.8% | Feb 27, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This... |
| CVE-2023-1059 | HIGH | 8.8 | 0.8% | Feb 27, 2023 | A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability af... |
| CVE-2023-1058 | HIGH | 8.8 | 0.8% | Feb 27, 2023 | A vulnerability classified as critical has been found in SourceCodester Doctors Appointment System 1.0. This affects an ... |
| CVE-2023-1057 | HIGH | 8.8 | 0.7% | Feb 27, 2023 | A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been rated as critical. Affected by t... |
| CVE-2023-1056 | HIGH | 8.8 | 0.7% | Feb 27, 2023 | A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected b... |
| CVE-2023-26257 | HIGH | 7.5 | 1.2% | Feb 27, 2023 | An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. D... |
| CVE-2023-26609 | HIGH | 7.2 | 38.7% | Feb 27, 2023 | ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin... |
| CVE-2023-26607 | HIGH | 7.1 | 0.6% | Feb 26, 2023 | In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. |
| CVE-2023-26606 | HIGH | 7.8 | 0.4% | Feb 26, 2023 | In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now