2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39654 | CRITICAL | 9.8 | 0.7% | Sep 5, 2023 | abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.se... |
| CVE-2023-4781 | HIGH | 7.8 | 0.6% | Sep 5, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. |
| CVE-2023-4531 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-... |
| CVE-2023-4178 | CRITICAL | 9.8 | 0.6% | Sep 5, 2023 | Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue a... |
| CVE-2023-4034 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information... |
| CVE-2023-41317 | MEDIUM | 5.9 | 0.7% | Sep 5, 2023 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that us... |
| CVE-2023-40918 | HIGH | 8.8 | 0.6% | Sep 5, 2023 | KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin ro... |
| CVE-2023-3616 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hote... |
| CVE-2023-39681 | CRITICAL | 9.8 | 1.4% | Sep 5, 2023 | Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at... |
| CVE-2023-39598 | MEDIUM | 6.1 | 1.4% | Sep 5, 2023 | Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitra... |
| CVE-2023-35072 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proag... |
| CVE-2023-35068 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Trac... |
| CVE-2023-35065 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Produc... |
| CVE-2023-3375 | HIGH | 7.2 | 1.2% | Sep 5, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This iss... |
| CVE-2023-3374 | CRITICAL | 9.8 | 0.6% | Sep 5, 2023 | Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects ... |
| CVE-2023-35124 | MEDIUM | 4.3 | 0.5% | Sep 5, 2023 | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati... |
| CVE-2023-34998 | HIGH | 8.1 | 1.2% | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v... |
| CVE-2023-34994 | MEDIUM | 4.3 | 0.7% | Sep 5, 2023 | An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Au... |
| CVE-2023-34353 | HIGH | 7.5 | 1.0% | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software... |
| CVE-2023-34317 | MEDIUM | 6.5 | 0.8% | Sep 5, 2023 | An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Softw... |
| CVE-2023-32615 | HIGH | 8.1 | 0.7% | Sep 5, 2023 | A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform... |
| CVE-2023-32271 | MEDIUM | 6.5 | 0.9% | Sep 5, 2023 | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati... |
| CVE-2023-31242 | CRITICAL | 9.8 | 3.4% | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v... |
| CVE-2023-4778 | MEDIUM | 5.5 | 0.3% | Sep 5, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-41108 | HIGH | 8.8 | 1.3% | Sep 5, 2023 | TEF portal 2023-07-17 is vulnerable to authenticated remote code execution. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now