2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35084 | CRITICAL | 9.8 | 2.8% | Oct 18, 2023 | Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 ... |
| CVE-2023-41630 | CRITICAL | 9.8 | 1.2% | Oct 17, 2023 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generato... |
| CVE-2023-22089 | CRITICAL | 9.8 | 0.7% | Oct 17, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2023-22072 | CRITICAL | 9.8 | 0.6% | Oct 17, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported versi... |
| CVE-2023-22069 | CRITICAL | 9.8 | 0.8% | Oct 17, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2023-45952 | CRITICAL | 9.8 | 0.8% | Oct 17, 2023 | An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute ... |
| CVE-2023-45951 | CRITICAL | 9.8 | 0.7% | Oct 17, 2023 | lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php. |
| CVE-2023-27133 | CRITICAL | 9.8 | 0.8% | Oct 17, 2023 | TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-Rem... |
| CVE-2023-27132 | CRITICAL | 9.8 | 0.9% | Oct 17, 2023 | TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure si... |
| CVE-2023-44694 | CRITICAL | 9.8 | 0.7% | Oct 17, 2023 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php. |
| CVE-2023-44693 | CRITICAL | 9.8 | 13.3% | Oct 17, 2023 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. |
| CVE-2023-45386 | CRITICAL | 9.8 | 0.6% | Oct 17, 2023 | In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `... |
| CVE-2023-45144 | CRITICAL | 9.6 | 1.1% | Oct 16, 2023 | com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth... |
| CVE-2023-40852 | CRITICAL | 9.8 | 0.8% | Oct 16, 2023 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allo... |
| CVE-2023-4666 | CRITICAL | 9.8 | 3.3% | Oct 16, 2023 | The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server fr... |
| CVE-2023-43119 | CRITICAL | 9.8 | 0.6% | Oct 16, 2023 | An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 ... |
| CVE-2023-45984 | CRITICAL | 9.8 | 0.7% | Oct 16, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack over... |
| CVE-2023-45685 | CRITICAL | 9.1 | 1.4% | Oct 16, 2023 | Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers... |
| CVE-2023-20198 | CRITICAL | 10 | 99.6% | Oct 16, 2023 | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS... |
| CVE-2023-3991 | CRITICAL | 9.8 | 2.4% | Oct 16, 2023 | An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially ... |
| CVE-2023-5422 | CRITICAL | 9.1 | 0.3% | Oct 16, 2023 | The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS base... |
| CVE-2023-43668 | CRITICAL | 9.8 | 1.0% | Oct 16, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1... |
| CVE-2023-45158 | CRITICAL | 9.8 | 3.7% | Oct 16, 2023 | An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifyS... |
| CVE-2023-45580 | CRITICAL | 9.8 | 1.2% | Oct 16, 2023 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and be... |
| CVE-2023-45579 | CRITICAL | 9.8 | 1.2% | Oct 16, 2023 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and be... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now