2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36735 | CRITICAL | 9.6 | 1.9% | Sep 15, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-41887 | CRITICAL | 9.8 | 45.5% | Sep 15, 2023 | OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execu... |
| CVE-2023-0923 | CRITICAL | 9.8 | 0.9% | Sep 15, 2023 | A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces ... |
| CVE-2023-38507 | CRITICAL | 9.8 | 0.8% | Sep 15, 2023 | Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the l... |
| CVE-2023-42398 | CRITICAL | 9.8 | 1.3% | Sep 15, 2023 | An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ued... |
| CVE-2023-28614 | CRITICAL | 9.8 | 2.3% | Sep 15, 2023 | Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page. |
| CVE-2023-4988 | CRITICAL | 9.8 | 0.5% | Sep 15, 2023 | A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of ... |
| CVE-2023-4835 | CRITICAL | 9.8 | 0.5% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CF Software Oil Ma... |
| CVE-2023-4833 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Ma... |
| CVE-2023-4662 | CRITICAL | 9.8 | 1.2% | Sep 15, 2023 | Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue... |
| CVE-2023-4661 | CRITICAL | 9.8 | 0.8% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Co... |
| CVE-2023-4831 | CRITICAL | 9.8 | 0.5% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows ... |
| CVE-2023-4670 | CRITICAL | 9.8 | 0.5% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys all... |
| CVE-2023-4231 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics ... |
| CVE-2023-4830 | CRITICAL | 9.8 | 0.5% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allo... |
| CVE-2023-4673 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasista... |
| CVE-2023-36659 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows r... |
| CVE-2023-36657 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrat... |
| CVE-2023-4974 | CRITICAL | 9.8 | 4.9% | Sep 15, 2023 | A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown func... |
| CVE-2023-39643 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml... |
| CVE-2023-39642 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCat... |
| CVE-2023-39641 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component Psaffi... |
| CVE-2023-39639 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::get... |
| CVE-2023-42405 | CRITICAL | 9.8 | 1.0% | Sep 14, 2023 | SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` para... |
| CVE-2023-39638 | CRITICAL | 9.8 | 3.0% | Sep 14, 2023 | D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now