2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-20036CRITICAL9.9A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands w...
CVE-2023-52268CRITICAL9.1The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user...
CVE-2023-27195CRITICAL9.8Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th...
CVE-2023-52044CRITICAL9.8Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files wi...
CVE-2023-26785CRITICAL9.8MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File...
CVE-2023-32191CRITICAL9.9When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-s...
CVE-2023-32188CRITICAL9.4A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ...
CVE-2023-48082CRITICAL9.1Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers...
CVE-2023-25581CRITICAL9.2pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulner...
CVE-2023-46586CRITICAL9.1cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strn...
CVE-2023-52952CRITICAL9.3A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiM...
CVE-2023-26770CRITICAL9.8TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan...
CVE-2023-3441CRITICAL9.1An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not s...
CVE-2023-26689CRITICAL9.8An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted ...
CVE-2023-26686CRITICAL9.8File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo...
CVE-2023-27584CRITICAL9.8Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native ...
CVE-2023-37234CRITICAL9.8Loftware Spectrum through 4.6 has unprotected JMX Registry.
CVE-2023-36103CRITICAL9.8Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run...
CVE-2023-37231CRITICAL9.8Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
CVE-2023-37227CRITICAL9.8Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
CVE-2023-37226CRITICAL9.8Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
CVE-2023-26324CRITICAL9.8A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri...
CVE-2023-26323CRITICAL9.8A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configurat...
CVE-2023-26322CRITICAL9.8A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri...
CVE-2023-26321CRITICAL9.8A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnera...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now