2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49946 | CRITICAL | 9.1 | 0.9% | Dec 3, 2023 | In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissio... |
| CVE-2023-6464 | CRITICAL | 9.8 | 0.8% | Dec 2, 2023 | A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected ... |
| CVE-2023-48887 | CRITICAL | 9.8 | 1.6% | Dec 1, 2023 | A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted R... |
| CVE-2023-48886 | CRITICAL | 9.8 | 1.4% | Dec 1, 2023 | A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RP... |
| CVE-2023-48801 | CRITICAL | 9.8 | 1.7% | Dec 1, 2023 | In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-en... |
| CVE-2023-44382 | CRITICAL | 9.1 | 0.9% | Dec 1, 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated back... |
| CVE-2023-48842 | CRITICAL | 9.8 | 3.7% | Dec 1, 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at... |
| CVE-2023-49371 | CRITICAL | 9.8 | 3.7% | Dec 1, 2023 | RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit. |
| CVE-2023-5636 | CRITICAL | 9.8 | 1.7% | Dec 1, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. ... |
| CVE-2023-5634 | CRITICAL | 9.8 | 0.8% | Dec 1, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Educati... |
| CVE-2023-43455 | CRITICAL | 9.8 | 1.5% | Dec 1, 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr... |
| CVE-2023-43454 | CRITICAL | 9.8 | 1.5% | Dec 1, 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr... |
| CVE-2023-43453 | CRITICAL | 9.8 | 1.5% | Dec 1, 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr... |
| CVE-2023-5908 | CRITICAL | 9.1 | 1.0% | Nov 30, 2023 | KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or l... |
| CVE-2023-47207 | CRITICAL | 9.8 | 16.6% | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to... |
| CVE-2023-39226 | CRITICAL | 9.8 | 1.2% | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to... |
| CVE-2023-6354 | CRITICAL | 9.4 | 1.0% | Nov 30, 2023 | Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, a... |
| CVE-2023-6353 | CRITICAL | 9.4 | 1.0% | Nov 30, 2023 | Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, an... |
| CVE-2023-6342 | CRITICAL | 9.8 | 1.1% | Nov 30, 2023 | Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at le... |
| CVE-2023-48812 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through... |
| CVE-2023-48811 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48810 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48808 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48807 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
| CVE-2023-48806 | CRITICAL | 9.8 | 1.5% | Nov 30, 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now