2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43654 | CRITICAL | 9.8 | 35.3% | Sep 28, 2023 | TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper... |
| CVE-2023-44166 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'age' parameter of the process_registration.php resource does not validate the characters received and they are se... |
| CVE-2023-44164 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent un... |
| CVE-2023-44163 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent ... |
| CVE-2023-43739 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfilter... |
| CVE-2023-5053 | CRITICAL | 9.8 | 0.9% | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is... |
| CVE-2023-5004 | CRITICAL | 9.8 | 0.9% | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is... |
| CVE-2023-43013 | CRITICAL | 9.8 | 0.7% | Sep 28, 2023 | Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter ... |
| CVE-2023-30415 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the... |
| CVE-2023-43869 | CRITICAL | 9.8 | 1.0% | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function. |
| CVE-2023-44273 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and EC... |
| CVE-2023-38870 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book ha... |
| CVE-2023-41449 | CRITICAL | 9.8 | 1.5% | Sep 27, 2023 | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t... |
| CVE-2023-44080 | CRITICAL | 9.8 | 0.9% | Sep 27, 2023 | An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request... |
| CVE-2023-43656 | CRITICAL | 9 | 0.3% | Sep 27, 2023 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that ... |
| CVE-2023-43651 | CRITICAL | 9.9 | 1.7% | Sep 27, 2023 | JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to exec... |
| CVE-2023-42818 | CRITICAL | 9.8 | 0.6% | Sep 27, 2023 | JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH s... |
| CVE-2023-43652 | CRITICAL | 9.1 | 0.7% | Sep 27, 2023 | JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi... |
| CVE-2023-20252 | CRITICAL | 9.8 | 1.1% | Sep 27, 2023 | A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al... |
| CVE-2023-20186 | CRITICAL | 9.1 | 0.6% | Sep 27, 2023 | A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS X... |
| CVE-2023-5223 | CRITICAL | 9.9 | 0.9% | Sep 27, 2023 | A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects s... |
| CVE-2023-5222 | CRITICAL | 9.8 | 74.7% | Sep 27, 2023 | A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the... |
| CVE-2023-5221 | CRITICAL | 9.8 | 1.3% | Sep 27, 2023 | A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/ind... |
| CVE-2023-5176 | CRITICAL | 9.8 | 1.2% | Sep 27, 2023 | Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence ... |
| CVE-2023-5175 | CRITICAL | 9.8 | 0.8% | Sep 27, 2023 | During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed fr... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now