2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-5766CRITICAL9.8 A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to...
CVE-2023-5765CRITICAL9.8Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on ...
CVE-2023-20048CRITICAL9.9A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent...
CVE-2023-1719CRITICAL9.8Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers...
CVE-2023-1717CRITICAL9.6 Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 al...
CVE-2023-1716CRITICAL9.6 Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrar...
CVE-2023-46485CRITICAL9.8An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracero...
CVE-2023-46484CRITICAL9.8An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg ...
CVE-2023-46256CRITICAL9.8PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a hea...
CVE-2023-46249CRITICAL9.8authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has...
CVE-2023-46993CRITICAL9.8In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable ...
CVE-2023-42425CRITICAL9.8An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensit...
CVE-2023-37966CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us...
CVE-2023-36508CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contac...
CVE-2023-35879CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Produc...
CVE-2023-33927CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple...
CVE-2023-31212CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database...
CVE-2023-24410CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPM...
CVE-2023-22518CRITICAL9.8All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz...
CVE-2023-5360CRITICAL9.8The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which...
CVE-2023-46979CRITICAL9.8TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parame...
CVE-2023-46977CRITICAL9.8TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the fu...
CVE-2023-46976CRITICAL9.8TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFil...
CVE-2023-24000CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipres...
CVE-2023-43139CRITICAL9.8An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now