2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4849 | CRITICAL | 9.8 | 0.6% | Sep 9, 2023 | A vulnerability, which was classified as critical, has been found in IBOS OA 4.5.5. Affected by this issue is some unkno... |
| CVE-2023-4848 | CRITICAL | 9.8 | 0.8% | Sep 9, 2023 | A vulnerability classified as critical was found in SourceCodester Simple Book Catalog App 1.0. Affected by this vulnera... |
| CVE-2023-4845 | CRITICAL | 9.8 | 0.6% | Sep 9, 2023 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnera... |
| CVE-2023-42277 | CRITICAL | 9.8 | 0.8% | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. |
| CVE-2023-42276 | CRITICAL | 9.8 | 0.8% | Sep 8, 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. |
| CVE-2023-42268 | CRITICAL | 9.8 | 0.7% | Sep 8, 2023 | Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/s... |
| CVE-2023-39320 | CRITICAL | 9.8 | 1.4% | Sep 8, 2023 | The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the ... |
| CVE-2023-41615 | CRITICAL | 9.8 | 0.8% | Sep 8, 2023 | Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page vi... |
| CVE-2023-37759 | CRITICAL | 9.8 | 3.6% | Sep 8, 2023 | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat... |
| CVE-2023-40029 | CRITICAL | 9.6 | 1.0% | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us... |
| CVE-2023-30908 | CRITICAL | 9.8 | 1.2% | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. |
| CVE-2023-40942 | CRITICAL | 9.8 | 0.7% | Sep 7, 2023 | Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/Set... |
| CVE-2023-39423 | CRITICAL | 9.1 | 0.5% | Sep 7, 2023 | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using ... |
| CVE-2023-39422 | CRITICAL | 9.8 | 0.4% | Sep 7, 2023 | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. ... |
| CVE-2023-40397 | CRITICAL | 9.8 | 1.4% | Sep 6, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able t... |
| CVE-2023-39967 | CRITICAL | 10 | 0.8% | Sep 6, 2023 | WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Stud... |
| CVE-2023-23623 | CRITICAL | 9.8 | 0.7% | Sep 6, 2023 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Conte... |
| CVE-2023-41330 | CRITICAL | 9.8 | 1.9% | Sep 6, 2023 | knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue ... |
| CVE-2023-20269 | CRITICAL | 9.1 | 21.6% | Sep 6, 2023 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower... |
| CVE-2023-20238 | CRITICAL | 9.8 | 15.3% | Sep 6, 2023 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco B... |
| CVE-2023-0925 | CRITICAL | 9.8 | 0.6% | Sep 6, 2023 | Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry ... |
| CVE-2023-41149 | CRITICAL | 9.8 | 1.3% | Sep 6, 2023 | F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploit... |
| CVE-2023-4634 | CRITICAL | 9.8 | 82.6% | Sep 6, 2023 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers... |
| CVE-2023-30723 | CRITICAL | 9.8 | 0.4% | Sep 6, 2023 | Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrar... |
| CVE-2023-4485 | CRITICAL | 9.8 | 0.6% | Sep 6, 2023 | ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL inject... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now