2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36479LOW3.1Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a ver...
CVE-2023-36472MEDIUM5.7Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get acce...
CVE-2023-42398CRITICAL9.8An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ued...
CVE-2023-28614CRITICAL9.8Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.
CVE-2023-4991HIGH7.8A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknow...
CVE-2023-4988CRITICAL9.8A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of ...
CVE-2023-4987HIGH8A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue...
CVE-2023-4986LOW2.5A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerabili...
CVE-2023-4985HIGH7.8A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown fun...
CVE-2023-4984MEDIUM6.5A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some un...
CVE-2023-4983MEDIUM6.1A vulnerability was found in app1pro Shopicial up to 20230830. It has been declared as problematic. This vulnerability a...
CVE-2023-42270HIGH8.8Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-4959MEDIUM6.5A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an appli...
CVE-2023-4835CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CF Software Oil Ma...
CVE-2023-4833CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Ma...
CVE-2023-4665HIGH8.8Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This iss...
CVE-2023-4664HIGH8.8Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects ...
CVE-2023-4663MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect a...
CVE-2023-4662CRITICAL9.8Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue...
CVE-2023-4661CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Co...
CVE-2023-4831CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows ...
CVE-2023-4670CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys all...
CVE-2023-4231CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics ...
CVE-2023-32461MEDIUM6.7 Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high ...
CVE-2023-4830CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now