2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-46158CRITICAL9.8IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to i...
CVE-2023-46010CRITICAL9.8An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
CVE-2023-45554CRITICAL9.8File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the i...
CVE-2023-44794CRITICAL9.8An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payl...
CVE-2023-43795CRITICAL9.8GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC...
CVE-2023-42494CRITICAL9.8 EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
CVE-2023-42493CRITICAL9.8 EisBaer Scada - CWE-256: Plaintext Storage of a Password
CVE-2023-42492CRITICAL9.8 EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
CVE-2023-42491CRITICAL9.8EisBaer Scada - CWE-285: Improper Authorization
CVE-2023-42489CRITICAL9.8 EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
CVE-2023-39930CRITICAL9.8A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authe...
CVE-2023-37908CRITICAL9.6XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cle...
CVE-2023-37283CRITICAL9.8Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Iden...
CVE-2023-34048CRITICAL9.8vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious a...
CVE-2023-31581CRITICAL9.8Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
CVE-2023-30912CRITICAL9.8 A remote code execution issue exists in HPE OneView.
CVE-2023-27262CRITICAL9.1Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier...
CVE-2023-27260CRITICAL9.1Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier...
CVE-2023-27255CRITICAL9.1Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier ...
CVE-2023-27254CRITICAL9.1Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allo...
CVE-2023-26584CRITICAL9.1Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and ea...
CVE-2023-26583CRITICAL9.1Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allo...
CVE-2023-26582CRITICAL9.1Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier al...
CVE-2023-26581CRITICAL9.1Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extr...
CVE-2023-26573CRITICAL9.1Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now