2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36092 | CRITICAL | 9.8 | 1.1% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via ... |
| CVE-2023-36091 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via ... |
| CVE-2023-36090 | CRITICAL | 9.8 | 1.1% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via... |
| CVE-2023-36089 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated pr... |
| CVE-2023-34872 | MEDIUM | 5.5 | 0.9% | Jul 31, 2023 | A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (... |
| CVE-2023-34842 | CRITICAL | 9.8 | 1.0% | Jul 31, 2023 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted... |
| CVE-2023-34644 | CRITICAL | 9.8 | 1.5% | Jul 31, 2023 | Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204... |
| CVE-2023-34635 | CRITICAL | 9.8 | 2.1% | Jul 31, 2023 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not vali... |
| CVE-2023-33534 | HIGH | 8.8 | 0.3% | Jul 31, 2023 | A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.... |
| CVE-2023-37647 | CRITICAL | 9.8 | 0.6% | Jul 31, 2023 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. |
| CVE-2023-35861 | CRITICAL | 9.8 | 1.5% | Jul 31, 2023 | A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) all... |
| CVE-2023-3508 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which ... |
| CVE-2023-3507 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could ... |
| CVE-2023-3345 | MEDIUM | 6.5 | 1.9% | Jul 31, 2023 | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoi... |
| CVE-2023-3292 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outp... |
| CVE-2023-3134 | MEDIUM | 6.1 | 3.5% | Jul 31, 2023 | The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form field... |
| CVE-2023-3130 | MEDIUM | 4.8 | 0.4% | Jul 31, 2023 | The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-0602 | MEDIUM | 6.1 | 0.9% | Jul 31, 2023 | The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the... |
| CVE-2023-34360 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U run... |
| CVE-2023-34359 | HIGH | 7.5 | 0.6% | Jul 31, 2023 | ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req... |
| CVE-2023-34358 | HIGH | 7.5 | 0.6% | Jul 31, 2023 | ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req... |
| CVE-2023-24971 | MEDIUM | 6.5 | 0.7% | Jul 31, 2023 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to caus... |
| CVE-2023-22595 | MEDIUM | 5.4 | 0.3% | Jul 31, 2023 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-sit... |
| CVE-2023-4007 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16. |
| CVE-2023-4006 | CRITICAL | 9.8 | 0.7% | Jul 31, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now