2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43374 | CRITICAL | 9.8 | 3.3% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid... |
| CVE-2023-43373 | CRITICAL | 9.8 | 3.8% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/... |
| CVE-2023-43371 | CRITICAL | 9.8 | 0.9% | Sep 20, 2023 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/cr... |
| CVE-2023-40619 | CRITICAL | 9.8 | 1.1% | Sep 20, 2023 | phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution... |
| CVE-2023-5074 | CRITICAL | 9.8 | 67.9% | Sep 20, 2023 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Li... |
| CVE-2023-2262 | CRITICAL | 9.8 | 1.0% | Sep 20, 2023 | A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited... |
| CVE-2023-42464 | CRITICAL | 9.8 | 1.8% | Sep 20, 2023 | A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When pa... |
| CVE-2023-43478 | CRITICAL | 9.8 | 17.4% | Sep 20, 2023 | fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated... |
| CVE-2023-43207 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upl... |
| CVE-2023-43206 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_d... |
| CVE-2023-43204 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50.... |
| CVE-2023-43203 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users. |
| CVE-2023-43202 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_downl... |
| CVE-2023-43201 | CRITICAL | 9.8 | 0.9% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ex... |
| CVE-2023-43200 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data... |
| CVE-2023-43199 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/logi... |
| CVE-2023-43198 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/h... |
| CVE-2023-43197 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.as... |
| CVE-2023-43196 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp f... |
| CVE-2023-0462 | CRITICAL | 9.1 | 1.0% | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on t... |
| CVE-2023-0118 | CRITICAL | 9.1 | 1.4% | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates a... |
| CVE-2023-0829 | CRITICAL | 9 | 0.6% | Sep 20, 2023 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a cu... |
| CVE-2023-38888 | CRITICAL | 9.6 | 1.2% | Sep 20, 2023 | Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive ... |
| CVE-2023-31009 | CRITICAL | 9.8 | 0.6% | Sep 20, 2023 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation.... |
| CVE-2023-25534 | CRITICAL | 9.8 | 0.5% | Sep 20, 2023 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now