2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-38912CRITICAL9.8SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code vi...
CVE-2023-37756CRITICAL9.8I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creatio...
CVE-2023-4972CRITICAL9.8Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This is...
CVE-2023-4702CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa...
CVE-2023-37755CRITICAL9.8i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and...
CVE-2023-4766CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL I...
CVE-2023-4669CRITICAL9.8Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. Th...
CVE-2023-41011CRITICAL9.8Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a...
CVE-2023-4832CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Mana...
CVE-2023-30909CRITICAL9.8A remote authentication bypass issue exists in some OneView APIs.
CVE-2023-38204CRITICAL9.8Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deseria...
CVE-2023-41892CRITICAL9.8Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users run...
CVE-2023-3935CRITICAL9.8A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthentic...
CVE-2023-39073CRITICAL9.8An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a ...
CVE-2023-41331CRITICAL9.8SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefull...
CVE-2023-3710CRITICAL9.8Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec...
CVE-2023-4501CRITICAL9.8User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL ...
CVE-2023-36765CRITICAL9.8Microsoft Office Elevation of Privilege Vulnerability
CVE-2023-36758CRITICAL9.8Visual Studio Elevation of Privilege Vulnerability
CVE-2023-29332CRITICAL9.8Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2023-40784CRITICAL9.8DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
CVE-2023-40834CRITICAL9.8OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, ...
CVE-2023-2071CRITICAL9.8 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which all...
CVE-2023-39150CRITICAL9.8ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to a...
CVE-2023-39637CRITICAL9.8D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnos...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now