2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39654CRITICAL9.8abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.se...
CVE-2023-4781HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
CVE-2023-4531CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-...
CVE-2023-4178CRITICAL9.8Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue a...
CVE-2023-4034CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information...
CVE-2023-41317MEDIUM5.9The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that us...
CVE-2023-40918HIGH8.8KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin ro...
CVE-2023-3616CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hote...
CVE-2023-39681CRITICAL9.8Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at...
CVE-2023-39598MEDIUM6.1Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitra...
CVE-2023-35072CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proag...
CVE-2023-35068CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Trac...
CVE-2023-35065CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Produc...
CVE-2023-3375HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This iss...
CVE-2023-3374CRITICAL9.8Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects ...
CVE-2023-35124MEDIUM4.3An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati...
CVE-2023-34998HIGH8.1An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v...
CVE-2023-34994MEDIUM4.3An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Au...
CVE-2023-34353HIGH7.5An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software...
CVE-2023-34317MEDIUM6.5An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Softw...
CVE-2023-32615HIGH8.1A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform...
CVE-2023-32271MEDIUM6.5An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati...
CVE-2023-31242CRITICAL9.8An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v...
CVE-2023-4778MEDIUM5.5Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-41108HIGH8.8TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now