2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-4257CRITICAL9.8Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
CVE-2023-45467CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Ti...
CVE-2023-45466CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS...
CVE-2023-45465CRITICAL9.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in t...
CVE-2023-45162CRITICAL9.8Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Appl...
CVE-2023-29464CRITICAL9.1 FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from m...
CVE-2023-5572CRITICAL9.8Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.
CVE-2023-4562CRITICAL9.1Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote un...
CVE-2023-41262CRITICAL9.8An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint actio...
CVE-2023-45138CRITICAL9.6Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Sta...
CVE-2023-5046CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ...
CVE-2023-5045CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ...
CVE-2023-23737CRITICAL9.8Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.
CVE-2023-5554CRITICAL9.8Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16...
CVE-2023-32723CRITICAL9.1Request to LDAP is sent before user permissions are checked.
CVE-2023-40833CRITICAL9.8An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSe...
CVE-2023-29453CRITICAL9.8Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Ba...
CVE-2023-45132CRITICAL9.8NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 a...
CVE-2023-35662CRITICAL9.8there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additio...
CVE-2023-35648CRITICAL9.8In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a...
CVE-2023-35647CRITICAL9.8In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a...
CVE-2023-35646CRITICAL9.8In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code e...
CVE-2023-35968CRITICAL9.8Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 ...
CVE-2023-35967CRITICAL9.8Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 ...
CVE-2023-35966CRITICAL9.8Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now