2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29074 | CRITICAL | 9.8 | 1.0% | Nov 23, 2023 | A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bou... |
| CVE-2023-29073 | CRITICAL | 9.8 | 1.0% | Nov 23, 2023 | A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Bu... |
| CVE-2023-46357 | CRITICAL | 9.8 | 0.7% | Nov 22, 2023 | In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can pe... |
| CVE-2023-45377 | CRITICAL | 9.8 | 0.7% | Nov 22, 2023 | In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `canc... |
| CVE-2023-5822 | CRITICAL | 9.8 | 1.8% | Nov 22, 2023 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2023-5815 | CRITICAL | 9.8 | 4.3% | Nov 22, 2023 | The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post... |
| CVE-2023-2449 | CRITICAL | 9.8 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T... |
| CVE-2023-2889 | CRITICAL | 9.8 | 0.7% | Nov 22, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Serv... |
| CVE-2023-5047 | CRITICAL | 9.8 | 0.7% | Nov 22, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing ... |
| CVE-2023-37924 | CRITICAL | 9.8 | 7.2% | Nov 22, 2023 | Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can resul... |
| CVE-2023-48699 | CRITICAL | 9.8 | 0.7% | Nov 21, 2023 | fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior ... |
| CVE-2023-48307 | CRITICAL | 9.8 | 0.9% | Nov 21, 2023 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior ... |
| CVE-2023-48306 | CRITICAL | 9.8 | 0.8% | Nov 21, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio... |
| CVE-2023-6248 | CRITICAL | 9.8 | 1.2% | Nov 21, 2023 | The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u... |
| CVE-2023-49105 | CRITICAL | 9.8 | 11.1% | Nov 21, 2023 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit... |
| CVE-2023-48230 | CRITICAL | 9.8 | 1.9% | Nov 21, 2023 | Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ H... |
| CVE-2023-48228 | CRITICAL | 9.8 | 1.2% | Nov 21, 2023 | authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method`... |
| CVE-2023-5055 | CRITICAL | 9.8 | 0.8% | Nov 21, 2023 | Possible variant of CVE-2021-3434 in function le_ecred_reconf_req. |
| CVE-2023-49060 | CRITICAL | 9.8 | 0.6% | Nov 21, 2023 | An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrer... |
| CVE-2023-4149 | CRITICAL | 9.8 | 1.1% | Nov 21, 2023 | A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system command... |
| CVE-2023-42770 | CRITICAL | 9.8 | 0.9% | Nov 21, 2023 | Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an... |
| CVE-2023-40151 | CRITICAL | 9.8 | 1.1% | Nov 21, 2023 | When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK ... |
| CVE-2023-48176 | CRITICAL | 9.8 | 0.9% | Nov 20, 2023 | An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jw... |
| CVE-2023-46990 | CRITICAL | 9.8 | 1.5% | Nov 20, 2023 | Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a c... |
| CVE-2023-38823 | CRITICAL | 9.8 | 1.2% | Nov 20, 2023 | Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to exec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now