2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5801 | CRITICAL | 9.1 | 0.4% | Nov 8, 2023 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnera... |
| CVE-2023-46800 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parame... |
| CVE-2023-46793 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' param... |
| CVE-2023-46789 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' ... |
| CVE-2023-46788 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parame... |
| CVE-2023-46787 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' ... |
| CVE-2023-46785 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parame... |
| CVE-2023-46679 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' pa... |
| CVE-2023-46677 | CRITICAL | 9.8 | 0.8% | Nov 7, 2023 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' paramete... |
| CVE-2023-5309 | CRITICAL | 9.8 | 0.5% | Nov 7, 2023 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for... |
| CVE-2023-46501 | CRITICAL | 9.1 | 1.3% | Nov 7, 2023 | An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a... |
| CVE-2023-47359 | CRITICAL | 9.8 | 1.1% | Nov 7, 2023 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in fun... |
| CVE-2023-23796 | CRITICAL | 9.8 | 0.5% | Nov 7, 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Conta... |
| CVE-2023-22719 | CRITICAL | 9.8 | 0.6% | Nov 7, 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a th... |
| CVE-2023-47456 | CRITICAL | 9.1 | 0.8% | Nov 7, 2023 | Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessR... |
| CVE-2023-47455 | CRITICAL | 9.1 | 0.8% | Nov 7, 2023 | Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are dire... |
| CVE-2023-33481 | CRITICAL | 9.8 | 0.7% | Nov 7, 2023 | RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index... |
| CVE-2023-33479 | CRITICAL | 9.8 | 0.7% | Nov 7, 2023 | RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file. |
| CVE-2023-33478 | CRITICAL | 9.8 | 0.7% | Nov 7, 2023 | RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php. |
| CVE-2023-42284 | CRITICAL | 9.8 | 1.2% | Nov 7, 2023 | Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the databas... |
| CVE-2023-42283 | CRITICAL | 9.8 | 1.3% | Nov 7, 2023 | Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via... |
| CVE-2023-38547 | CRITICAL | 9.8 | 18.9% | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ON... |
| CVE-2023-33045 | CRITICAL | 9.8 | 0.5% | Nov 7, 2023 | Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute. |
| CVE-2023-22388 | CRITICAL | 9.8 | 0.4% | Nov 7, 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
| CVE-2023-2675 | CRITICAL | 9.8 | 0.6% | Nov 7, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now