2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38912 | CRITICAL | 9.8 | 1.4% | Sep 14, 2023 | SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-37756 | CRITICAL | 9.8 | 1.2% | Sep 14, 2023 | I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creatio... |
| CVE-2023-4972 | CRITICAL | 9.8 | 0.6% | Sep 14, 2023 | Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This is... |
| CVE-2023-4702 | CRITICAL | 9.8 | 0.7% | Sep 14, 2023 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa... |
| CVE-2023-37755 | CRITICAL | 9.8 | 1.1% | Sep 14, 2023 | i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and... |
| CVE-2023-4766 | CRITICAL | 9.8 | 0.5% | Sep 14, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL I... |
| CVE-2023-4669 | CRITICAL | 9.8 | 1.0% | Sep 14, 2023 | Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. Th... |
| CVE-2023-41011 | CRITICAL | 9.8 | 2.0% | Sep 14, 2023 | Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a... |
| CVE-2023-4832 | CRITICAL | 9.8 | 0.5% | Sep 14, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Mana... |
| CVE-2023-30909 | CRITICAL | 9.8 | 1.1% | Sep 14, 2023 | A remote authentication bypass issue exists in some OneView APIs. |
| CVE-2023-38204 | CRITICAL | 9.8 | 65.5% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deseria... |
| CVE-2023-41892 | CRITICAL | 9.8 | 92.9% | Sep 13, 2023 | Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users run... |
| CVE-2023-3935 | CRITICAL | 9.8 | 1.5% | Sep 13, 2023 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthentic... |
| CVE-2023-39073 | CRITICAL | 9.8 | 0.9% | Sep 12, 2023 | An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a ... |
| CVE-2023-41331 | CRITICAL | 9.8 | 1.3% | Sep 12, 2023 | SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefull... |
| CVE-2023-3710 | CRITICAL | 9.8 | 33.1% | Sep 12, 2023 | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec... |
| CVE-2023-4501 | CRITICAL | 9.8 | 0.6% | Sep 12, 2023 | User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL ... |
| CVE-2023-36765 | CRITICAL | 9.8 | 1.0% | Sep 12, 2023 | Microsoft Office Elevation of Privilege Vulnerability |
| CVE-2023-36758 | CRITICAL | 9.8 | 1.4% | Sep 12, 2023 | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2023-29332 | CRITICAL | 9.8 | 2.8% | Sep 12, 2023 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2023-40784 | CRITICAL | 9.8 | 0.6% | Sep 12, 2023 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. |
| CVE-2023-40834 | CRITICAL | 9.8 | 1.1% | Sep 12, 2023 | OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, ... |
| CVE-2023-2071 | CRITICAL | 9.8 | 11.0% | Sep 12, 2023 | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which all... |
| CVE-2023-39150 | CRITICAL | 9.8 | 0.8% | Sep 12, 2023 | ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to a... |
| CVE-2023-39637 | CRITICAL | 9.8 | 2.1% | Sep 12, 2023 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnos... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now