2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-43654CRITICAL9.8TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper...
CVE-2023-44166CRITICAL9.8The 'age' parameter of the process_registration.php resource does not validate the characters received and they are se...
CVE-2023-44164CRITICAL9.8The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent un...
CVE-2023-44163CRITICAL9.8The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent ...
CVE-2023-43739CRITICAL9.8The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfilter...
CVE-2023-5053CRITICAL9.8Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is...
CVE-2023-5004CRITICAL9.8Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is...
CVE-2023-43013CRITICAL9.8Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter ...
CVE-2023-30415CRITICAL9.8Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
CVE-2023-43869CRITICAL9.8D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.
CVE-2023-44273CRITICAL9.8Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and EC...
CVE-2023-38870CRITICAL9.8A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book ha...
CVE-2023-41449CRITICAL9.8An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t...
CVE-2023-44080CRITICAL9.8An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request...
CVE-2023-43656CRITICAL9matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that ...
CVE-2023-43651CRITICAL9.9JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to exec...
CVE-2023-42818CRITICAL9.8JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH s...
CVE-2023-43652CRITICAL9.1JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi...
CVE-2023-20252CRITICAL9.8A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al...
CVE-2023-20186CRITICAL9.1A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS X...
CVE-2023-5223CRITICAL9.9A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects s...
CVE-2023-5222CRITICAL9.8A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the...
CVE-2023-5221CRITICAL9.8A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/ind...
CVE-2023-5176CRITICAL9.8Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence ...
CVE-2023-5175CRITICAL9.8During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed fr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now