2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-41507CRITICAL9.8Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component ...
CVE-2023-4310CRITICAL9.8BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injectio...
CVE-2023-41508CRITICAL9.8A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
CVE-2023-39361CRITICAL9.8Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL in...
CVE-2023-41009CRITICAL9.8File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2023-39654CRITICAL9.8abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.se...
CVE-2023-4531CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-...
CVE-2023-4178CRITICAL9.8Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue a...
CVE-2023-4034CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information...
CVE-2023-3616CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hote...
CVE-2023-39681CRITICAL9.8Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at...
CVE-2023-35072CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proag...
CVE-2023-35068CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Trac...
CVE-2023-35065CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Produc...
CVE-2023-3374CRITICAL9.8Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects ...
CVE-2023-31242CRITICAL9.8An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v...
CVE-2023-41012CRITICAL9.8An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to exe...
CVE-2023-36361CRITICAL9.8Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
CVE-2023-40743CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that lo...
CVE-2023-41910CRITICAL9.8An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a mal...
CVE-2023-28581CRITICAL9.8Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
CVE-2023-28562CRITICAL9.8Memory corruption while handling payloads from remote ESL.
CVE-2023-28543CRITICAL9.8A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted...
CVE-2023-35892CRITICAL9.1IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attac...
CVE-2023-41054CRITICAL9.1LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subjec...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now