2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-45480CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the...
CVE-2023-45479CRITICAL9.8Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in th...
CVE-2023-47462CRITICAL9.8Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary co...
CVE-2023-46886CRITICAL9.1Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary m...
CVE-2023-23325CRITICAL9.8Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the Ne...
CVE-2023-23324CRITICAL9.8Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator ...
CVE-2023-48193CRITICAL9.8Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via by...
CVE-2023-41264CRITICAL9.8Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on dep...
CVE-2023-49313CRITICAL9.8A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unaut...
CVE-2023-48023CRITICAL9.1Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant becau...
CVE-2023-48022CRITICAL9.8Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve...
CVE-2023-3545CRITICAL9.8Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installation...
CVE-2023-3533CRITICAL9.8Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20...
CVE-2023-3368CRITICAL9.8Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated at...
CVE-2023-47503CRITICAL9.8An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the log...
CVE-2023-48188CRITICAL9.8SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrar...
CVE-2023-46480CRITICAL9.8An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ...
CVE-2023-46349CRITICAL9.8In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop,...
CVE-2023-49044CRITICAL9.8Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid p...
CVE-2023-6329CRITICAL9.8An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll c...
CVE-2023-5974CRITICAL9.8The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parame...
CVE-2023-5604CRITICAL9.8The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administra...
CVE-2023-5559CRITICAL9.1The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing...
CVE-2023-4922CRITICAL9.8The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.
CVE-2023-49042CRITICAL9.8Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedSt...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now