2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-29074CRITICAL9.8A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bou...
CVE-2023-29073CRITICAL9.8A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Bu...
CVE-2023-46357CRITICAL9.8In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can pe...
CVE-2023-45377CRITICAL9.8In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `canc...
CVE-2023-5822CRITICAL9.8The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2023-5815CRITICAL9.8The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post...
CVE-2023-2449CRITICAL9.8The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T...
CVE-2023-2889CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Serv...
CVE-2023-5047CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing ...
CVE-2023-37924CRITICAL9.8Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can resul...
CVE-2023-48699CRITICAL9.8fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior ...
CVE-2023-48307CRITICAL9.8Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior ...
CVE-2023-48306CRITICAL9.8Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-6248CRITICAL9.8The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u...
CVE-2023-49105CRITICAL9.8An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit...
CVE-2023-48230CRITICAL9.8Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ H...
CVE-2023-48228CRITICAL9.8authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method`...
CVE-2023-5055CRITICAL9.8Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
CVE-2023-49060CRITICAL9.8An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrer...
CVE-2023-4149CRITICAL9.8A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system command...
CVE-2023-42770CRITICAL9.8 Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an...
CVE-2023-40151CRITICAL9.8 When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK ...
CVE-2023-48176CRITICAL9.8An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jw...
CVE-2023-46990CRITICAL9.8Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a c...
CVE-2023-38823CRITICAL9.8Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to exec...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now