2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41895 | CRITICAL | 9.6 | 0.7% | Oct 19, 2023 | Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Ass... |
| CVE-2023-30131 | CRITICAL | 9.8 | 0.8% | Oct 19, 2023 | An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege,... |
| CVE-2023-45376 | CRITICAL | 9.8 | 0.7% | Oct 19, 2023 | In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.... |
| CVE-2023-43492 | CRITICAL | 9.8 | 0.9% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which ... |
| CVE-2023-38584 | CRITICAL | 9.8 | 1.1% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which... |
| CVE-2023-45992 | CRITICAL | 9.6 | 0.6% | Oct 19, 2023 | A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could... |
| CVE-2023-45381 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform... |
| CVE-2023-43986 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component Configur... |
| CVE-2023-45278 | CRITICAL | 9.1 | 1.6% | Oct 19, 2023 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbi... |
| CVE-2023-46042 | CRITICAL | 9.8 | 22.6% | Oct 19, 2023 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinf... |
| CVE-2023-35187 | CRITICAL | 9.8 | 3.0% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerabil... |
| CVE-2023-35184 | CRITICAL | 9.8 | 1.4% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a... |
| CVE-2023-35182 | CRITICAL | 9.8 | 2.4% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be a... |
| CVE-2023-45384 | CRITICAL | 9.8 | 0.6% | Oct 19, 2023 | KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the modu... |
| CVE-2023-45379 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can pe... |
| CVE-2023-37503 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access... |
| CVE-2023-45146 | CRITICAL | 10 | 1.0% | Oct 18, 2023 | XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework ... |
| CVE-2023-4601 | CRITICAL | 9.8 | 0.6% | Oct 18, 2023 | A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosur... |
| CVE-2023-45911 | CRITICAL | 9.8 | 0.8% | Oct 18, 2023 | An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user wi... |
| CVE-2023-5642 | CRITICAL | 9.8 | 16.7% | Oct 18, 2023 | Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, whi... |
| CVE-2023-46007 | CRITICAL | 9.8 | 0.7% | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php... |
| CVE-2023-46006 | CRITICAL | 9.8 | 0.7% | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php. |
| CVE-2023-46005 | CRITICAL | 9.8 | 0.7% | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.ph... |
| CVE-2023-39332 | CRITICAL | 9.8 | 1.8% | Oct 18, 2023 | Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, t... |
| CVE-2023-38545 | CRITICAL | 9.8 | 78.5% | Oct 18, 2023 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the h... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now