2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4257 | CRITICAL | 9.8 | 0.9% | Oct 13, 2023 | Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows. |
| CVE-2023-45467 | CRITICAL | 9.8 | 1.9% | Oct 13, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Ti... |
| CVE-2023-45466 | CRITICAL | 9.8 | 1.9% | Oct 13, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS... |
| CVE-2023-45465 | CRITICAL | 9.8 | 1.8% | Oct 13, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in t... |
| CVE-2023-45162 | CRITICAL | 9.8 | 0.6% | Oct 13, 2023 | Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution. Appl... |
| CVE-2023-29464 | CRITICAL | 9.1 | 9.6% | Oct 13, 2023 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from m... |
| CVE-2023-5572 | CRITICAL | 9.8 | 0.8% | Oct 13, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0. |
| CVE-2023-4562 | CRITICAL | 9.1 | 0.9% | Oct 13, 2023 | Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote un... |
| CVE-2023-41262 | CRITICAL | 9.8 | 0.7% | Oct 12, 2023 | An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint actio... |
| CVE-2023-45138 | CRITICAL | 9.6 | 71.2% | Oct 12, 2023 | Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Sta... |
| CVE-2023-5046 | CRITICAL | 9.8 | 0.6% | Oct 12, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ... |
| CVE-2023-5045 | CRITICAL | 9.8 | 0.6% | Oct 12, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ... |
| CVE-2023-23737 | CRITICAL | 9.8 | 0.6% | Oct 12, 2023 | Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions. |
| CVE-2023-5554 | CRITICAL | 9.8 | 0.2% | Oct 12, 2023 | Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16... |
| CVE-2023-32723 | CRITICAL | 9.1 | 0.6% | Oct 12, 2023 | Request to LDAP is sent before user permissions are checked. |
| CVE-2023-40833 | CRITICAL | 9.8 | 0.7% | Oct 12, 2023 | An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSe... |
| CVE-2023-29453 | CRITICAL | 9.8 | 0.8% | Oct 12, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Ba... |
| CVE-2023-45132 | CRITICAL | 9.8 | 0.8% | Oct 11, 2023 | NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 a... |
| CVE-2023-35662 | CRITICAL | 9.8 | 0.4% | Oct 11, 2023 | there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additio... |
| CVE-2023-35648 | CRITICAL | 9.8 | 0.3% | Oct 11, 2023 | In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a... |
| CVE-2023-35647 | CRITICAL | 9.8 | 0.3% | Oct 11, 2023 | In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a... |
| CVE-2023-35646 | CRITICAL | 9.8 | 0.4% | Oct 11, 2023 | In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code e... |
| CVE-2023-35968 | CRITICAL | 9.8 | 0.8% | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 ... |
| CVE-2023-35967 | CRITICAL | 9.8 | 0.8% | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 ... |
| CVE-2023-35966 | CRITICAL | 9.8 | 0.8% | Oct 11, 2023 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now