2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-4849CRITICAL9.8A vulnerability, which was classified as critical, has been found in IBOS OA 4.5.5. Affected by this issue is some unkno...
CVE-2023-4848CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Simple Book Catalog App 1.0. Affected by this vulnera...
CVE-2023-4845CRITICAL9.8A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnera...
CVE-2023-42277CRITICAL9.8hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
CVE-2023-42276CRITICAL9.8hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
CVE-2023-42268CRITICAL9.8Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/s...
CVE-2023-39320CRITICAL9.8The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the ...
CVE-2023-41615CRITICAL9.8Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page vi...
CVE-2023-37759CRITICAL9.8Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat...
CVE-2023-40029CRITICAL9.6Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us...
CVE-2023-30908CRITICAL9.8A remote authentication bypass issue exists in a OneView API.
CVE-2023-40942CRITICAL9.8Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/Set...
CVE-2023-39423CRITICAL9.1The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using ...
CVE-2023-39422CRITICAL9.8The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. ...
CVE-2023-40397CRITICAL9.8The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able t...
CVE-2023-39967CRITICAL10WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Stud...
CVE-2023-23623CRITICAL9.8Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Conte...
CVE-2023-41330CRITICAL9.8knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue ...
CVE-2023-20269CRITICAL9.1A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower...
CVE-2023-20238CRITICAL9.8A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco B...
CVE-2023-0925CRITICAL9.8Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry ...
CVE-2023-41149CRITICAL9.8F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploit...
CVE-2023-4634CRITICAL9.8The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers...
CVE-2023-30723CRITICAL9.8Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrar...
CVE-2023-4485CRITICAL9.8ARDEREG ​Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL inject...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now