2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-43374CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid...
CVE-2023-43373CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/...
CVE-2023-43371CRITICAL9.8Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/cr...
CVE-2023-40619CRITICAL9.8phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution...
CVE-2023-5074CRITICAL9.8Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Li...
CVE-2023-2262CRITICAL9.8 A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited...
CVE-2023-42464CRITICAL9.8A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When pa...
CVE-2023-43478CRITICAL9.8fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated...
CVE-2023-43207CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upl...
CVE-2023-43206CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_d...
CVE-2023-43204CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50....
CVE-2023-43203CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.
CVE-2023-43202CRITICAL9.8D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_downl...
CVE-2023-43201CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ex...
CVE-2023-43200CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data...
CVE-2023-43199CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/logi...
CVE-2023-43198CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/h...
CVE-2023-43197CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.as...
CVE-2023-43196CRITICAL9.8D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp f...
CVE-2023-0462CRITICAL9.1An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on t...
CVE-2023-0118CRITICAL9.1An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates a...
CVE-2023-0829CRITICAL9Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a cu...
CVE-2023-38888CRITICAL9.6Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive ...
CVE-2023-31009CRITICAL9.8NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation....
CVE-2023-25534CRITICAL9.8NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now