2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-36529CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez ...
CVE-2023-25700CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS ...
CVE-2023-23369CRITICAL9.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-23368CRITICAL9.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-46980CRITICAL9.8An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile...
CVE-2023-46404CRITICAL9.9PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping ...
CVE-2023-3961CRITICAL9.8A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain socke...
CVE-2023-26015CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson M...
CVE-2023-25960CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – ...
CVE-2023-4591CRITICAL9.8A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an ...
CVE-2023-41652CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-3277CRITICAL9.8The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up...
CVE-2023-34383CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project ...
CVE-2023-5763CRITICAL9.8In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote ...
CVE-2023-41355CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An...
CVE-2023-41351CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote att...
CVE-2023-46817CRITICAL9.8An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not pro...
CVE-2023-43982CRITICAL9.8Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) ...
CVE-2023-41350CRITICAL9.8Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication a...
CVE-2023-38965CRITICAL9.8Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save U...
CVE-2023-36621CRITICAL9.1An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe ...
CVE-2023-46954CRITICAL9.8SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacke...
CVE-2023-46958CRITICAL9.8An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
CVE-2023-42299CRITICAL9.8Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and caus...
CVE-2023-31579CRITICAL9.8Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now