2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-6452CRITICAL9.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Sec...
CVE-2023-0714CRITICAL9.8The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file...
CVE-2023-20591CRITICAL10Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, all...
CVE-2023-26211CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 thro...
CVE-2023-7249CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Direct...
CVE-2023-48396CRITICAL9.1Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can...
CVE-2023-45249CRITICAL9.8Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct...
CVE-2023-40704CRITICAL9.8The product does not require unique and complex passwords to be created during installation. Using Philips's default pa...
CVE-2023-4976CRITICAL9.3A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an un...
CVE-2023-7012CRITICAL9.6Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convi...
CVE-2023-4860CRITICAL9.6Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromis...
CVE-2023-48194CRITICAL9.8Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After exec...
CVE-2023-46685CRITICAL9.8A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_1...
CVE-2023-24531CRITICAL9.8Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitiz...
CVE-2023-41921CRITICAL9.8A vulnerability allows attackers to download source code or an executable from a remote location and execute the code wi...
CVE-2023-41920CRITICAL9.8The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the devic...
CVE-2023-41919CRITICAL9.8Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauth...
CVE-2023-41918CRITICAL10A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this...
CVE-2023-41917CRITICAL10Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit thi...
CVE-2023-6198CRITICAL9.3Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows ...
CVE-2023-50029CRITICAL10PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaSh...
CVE-2023-45673CRITICAL9Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected...
CVE-2023-38389CRITICAL9.8Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained b...
CVE-2023-45197CRITICAL9.8The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the ro...
CVE-2023-36515CRITICAL9.8Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now