2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-35814CRITICAL9.8DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
CVE-2023-44755CRITICAL9.8Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacc...
CVE-2023-44752CRITICAL9.8An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET...
CVE-2023-43958CRITICAL9.8An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management ...
CVE-2023-25610CRITICAL9.8A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0...
CVE-2023-47539CRITICAL9.8An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wil...
CVE-2023-42784CRITICAL9.8An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7....
CVE-2023-38693CRITICAL9.8Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application devel...
CVE-2023-25574CRITICAL9.8`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticato...
CVE-2023-46271CRITICAL9.8Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises fr...
CVE-2023-34399CRITICAL9.8Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table...
CVE-2023-5878CRITICAL9.4Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2,...
CVE-2023-37398CRITICAL9.8IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes ...
CVE-2023-35907CRITICAL9.8IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes ...
CVE-2023-50316CRITICAL9.8IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote...
CVE-2023-46401CRITICAL9.8KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
CVE-2023-46400CRITICAL9.8KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
CVE-2023-37777CRITICAL9.8A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulner...
CVE-2023-27113CRITICAL9.8pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at pro...
CVE-2023-27112CRITICAL9.8pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project....
CVE-2023-37936CRITICAL9.8A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7....
CVE-2023-28354CRITICAL9.8An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff...
CVE-2023-52953CRITICAL9.1Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affec...
CVE-2023-47188CRITICAL9.8Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Confi...
CVE-2023-47183CRITICAL9.8Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Sec...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now