2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35814 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. |
| CVE-2023-44755 | CRITICAL | 9.8 | 0.5% | Apr 22, 2025 | Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacc... |
| CVE-2023-44752 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET... |
| CVE-2023-43958 | CRITICAL | 9.8 | 1.0% | Apr 22, 2025 | An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management ... |
| CVE-2023-25610 | CRITICAL | 9.8 | 17.8% | Mar 24, 2025 | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0... |
| CVE-2023-47539 | CRITICAL | 9.8 | 1.1% | Mar 18, 2025 | An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wil... |
| CVE-2023-42784 | CRITICAL | 9.8 | 0.4% | Mar 11, 2025 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.... |
| CVE-2023-38693 | CRITICAL | 9.8 | 0.8% | Mar 5, 2025 | Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application devel... |
| CVE-2023-25574 | CRITICAL | 9.8 | 0.3% | Feb 25, 2025 | `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticato... |
| CVE-2023-46271 | CRITICAL | 9.8 | 0.7% | Feb 19, 2025 | Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises fr... |
| CVE-2023-34399 | CRITICAL | 9.8 | 0.7% | Feb 13, 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table... |
| CVE-2023-5878 | CRITICAL | 9.4 | 0.9% | Feb 6, 2025 | Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2,... |
| CVE-2023-37398 | CRITICAL | 9.8 | 0.3% | Jan 29, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes ... |
| CVE-2023-35907 | CRITICAL | 9.8 | 0.3% | Jan 29, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes ... |
| CVE-2023-50316 | CRITICAL | 9.8 | 0.3% | Jan 28, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote... |
| CVE-2023-46401 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. |
| CVE-2023-46400 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. |
| CVE-2023-37777 | CRITICAL | 9.8 | 0.4% | Jan 22, 2025 | A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulner... |
| CVE-2023-27113 | CRITICAL | 9.8 | 0.5% | Jan 21, 2025 | pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at pro... |
| CVE-2023-27112 | CRITICAL | 9.8 | 0.5% | Jan 21, 2025 | pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.... |
| CVE-2023-37936 | CRITICAL | 9.8 | 1.0% | Jan 14, 2025 | A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.... |
| CVE-2023-28354 | CRITICAL | 9.8 | 1.2% | Jan 9, 2025 | An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff... |
| CVE-2023-52953 | CRITICAL | 9.1 | 0.3% | Jan 8, 2025 | Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affec... |
| CVE-2023-47188 | CRITICAL | 9.8 | 0.4% | Jan 2, 2025 | Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Confi... |
| CVE-2023-47183 | CRITICAL | 9.8 | 0.4% | Jan 2, 2025 | Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Sec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now