2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36529 | CRITICAL | 9.8 | 0.5% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez ... |
| CVE-2023-25700 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ... |
| CVE-2023-23369 | CRITICAL | 9.8 | 14.4% | Nov 3, 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-23368 | CRITICAL | 9.8 | 18.7% | Nov 3, 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-46980 | CRITICAL | 9.8 | 1.5% | Nov 3, 2023 | An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile... |
| CVE-2023-46404 | CRITICAL | 9.9 | 1.9% | Nov 3, 2023 | PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping ... |
| CVE-2023-3961 | CRITICAL | 9.8 | 2.4% | Nov 3, 2023 | A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain socke... |
| CVE-2023-26015 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson M... |
| CVE-2023-25960 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – ... |
| CVE-2023-4591 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an ... |
| CVE-2023-41652 | CRITICAL | 9.8 | 0.9% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-3277 | CRITICAL | 9.8 | 2.9% | Nov 3, 2023 | The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up... |
| CVE-2023-34383 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project ... |
| CVE-2023-5763 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote ... |
| CVE-2023-41355 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An... |
| CVE-2023-41351 | CRITICAL | 9.8 | 0.8% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote att... |
| CVE-2023-46817 | CRITICAL | 9.8 | 1.8% | Nov 3, 2023 | An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not pro... |
| CVE-2023-43982 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) ... |
| CVE-2023-41350 | CRITICAL | 9.8 | 0.8% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication a... |
| CVE-2023-38965 | CRITICAL | 9.8 | 1.3% | Nov 3, 2023 | Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save U... |
| CVE-2023-36621 | CRITICAL | 9.1 | 0.9% | Nov 3, 2023 | An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe ... |
| CVE-2023-46954 | CRITICAL | 9.8 | 1.1% | Nov 3, 2023 | SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacke... |
| CVE-2023-46958 | CRITICAL | 9.8 | 1.3% | Nov 2, 2023 | An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file. |
| CVE-2023-42299 | CRITICAL | 9.8 | 1.3% | Nov 2, 2023 | Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and caus... |
| CVE-2023-31579 | CRITICAL | 9.8 | 0.7% | Nov 2, 2023 | Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now