2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-35084CRITICAL9.8Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 ...
CVE-2023-41630CRITICAL9.8eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generato...
CVE-2023-22089CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2023-22072CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported versi...
CVE-2023-22069CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2023-45952CRITICAL9.8An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute ...
CVE-2023-45951CRITICAL9.8lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php.
CVE-2023-27133CRITICAL9.8TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-Rem...
CVE-2023-27132CRITICAL9.8TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure si...
CVE-2023-44694CRITICAL9.8D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.
CVE-2023-44693CRITICAL9.8D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.
CVE-2023-45386CRITICAL9.8In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `...
CVE-2023-45144CRITICAL9.6com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth...
CVE-2023-40852CRITICAL9.8SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allo...
CVE-2023-4666CRITICAL9.8The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server fr...
CVE-2023-43119CRITICAL9.8An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 ...
CVE-2023-45984CRITICAL9.8TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack over...
CVE-2023-45685CRITICAL9.1Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers...
CVE-2023-20198CRITICAL10Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS...
CVE-2023-3991CRITICAL9.8An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially ...
CVE-2023-5422CRITICAL9.1The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS base...
CVE-2023-43668CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1...
CVE-2023-45158CRITICAL9.8An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifyS...
CVE-2023-45580CRITICAL9.8Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and be...
CVE-2023-45579CRITICAL9.8Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and be...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now