2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-26572CRITICAL9.1Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows ...
CVE-2023-26569CRITICAL9.1Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and ea...
CVE-2023-26568CRITICAL9.1Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier ...
CVE-2023-37635CRITICAL9.8UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to ga...
CVE-2023-27152CRITICAL9.8DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack ...
CVE-2023-28805CRITICAL9.8An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue ...
CVE-2023-5700CRITICAL9.8A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affec...
CVE-2023-46322CRITICAL9.8iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial char...
CVE-2023-46321CRITICAL9.8iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell meta...
CVE-2023-5693CRITICAL9.8A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some u...
CVE-2023-46301CRITICAL9.8iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate...
CVE-2023-46300CRITICAL9.8iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate...
CVE-2023-5684CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Aff...
CVE-2023-5683CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue...
CVE-2023-45666CRITICAL9.8stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t g...
CVE-2023-5682CRITICAL9.8A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of ...
CVE-2023-37824CRITICAL9.8Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the comp...
CVE-2023-5533CRITICAL9.8The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o...
CVE-2023-5576CRITICAL9.3The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version...
CVE-2023-4488CRITICAL9.8The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via...
CVE-2023-4402CRITICAL9.8The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ...
CVE-2023-39680CRITICAL9.8Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar...
CVE-2023-34051CRITICAL9.8VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can...
CVE-2023-41897CRITICAL9.6Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, includin...
CVE-2023-41896CRITICAL9Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now