2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-49946CRITICAL9.1In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissio...
CVE-2023-6464CRITICAL9.8A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected ...
CVE-2023-48887CRITICAL9.8A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted R...
CVE-2023-48886CRITICAL9.8A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RP...
CVE-2023-48801CRITICAL9.8In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-en...
CVE-2023-44382CRITICAL9.1October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated back...
CVE-2023-48842CRITICAL9.8D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at...
CVE-2023-49371CRITICAL9.8RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
CVE-2023-5636CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. ...
CVE-2023-5634CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Educati...
CVE-2023-43455CRITICAL9.8An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr...
CVE-2023-43454CRITICAL9.8An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr...
CVE-2023-43453CRITICAL9.8An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitr...
CVE-2023-5908CRITICAL9.1 KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or l...
CVE-2023-47207CRITICAL9.8In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to...
CVE-2023-39226CRITICAL9.8In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to...
CVE-2023-6354CRITICAL9.4Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, a...
CVE-2023-6353CRITICAL9.4Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, an...
CVE-2023-6342CRITICAL9.8Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at le...
CVE-2023-48812CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through...
CVE-2023-48811CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug...
CVE-2023-48810CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug...
CVE-2023-48808CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug...
CVE-2023-48807CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug...
CVE-2023-48806CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end throug...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now