2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41507 | CRITICAL | 9.8 | 0.8% | Sep 5, 2023 | Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component ... |
| CVE-2023-4310 | CRITICAL | 9.8 | 1.4% | Sep 5, 2023 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injectio... |
| CVE-2023-41508 | CRITICAL | 9.8 | 1.1% | Sep 5, 2023 | A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. |
| CVE-2023-39361 | CRITICAL | 9.8 | 87.6% | Sep 5, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL in... |
| CVE-2023-41009 | CRITICAL | 9.8 | 1.7% | Sep 5, 2023 | File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted sc... |
| CVE-2023-39654 | CRITICAL | 9.8 | 0.7% | Sep 5, 2023 | abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.se... |
| CVE-2023-4531 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-... |
| CVE-2023-4178 | CRITICAL | 9.8 | 0.6% | Sep 5, 2023 | Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue a... |
| CVE-2023-4034 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information... |
| CVE-2023-3616 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hote... |
| CVE-2023-39681 | CRITICAL | 9.8 | 1.4% | Sep 5, 2023 | Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at... |
| CVE-2023-35072 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proag... |
| CVE-2023-35068 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Trac... |
| CVE-2023-35065 | CRITICAL | 9.8 | 0.5% | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Produc... |
| CVE-2023-3374 | CRITICAL | 9.8 | 0.6% | Sep 5, 2023 | Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects ... |
| CVE-2023-31242 | CRITICAL | 9.8 | 3.4% | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v... |
| CVE-2023-41012 | CRITICAL | 9.8 | 1.3% | Sep 5, 2023 | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to exe... |
| CVE-2023-36361 | CRITICAL | 9.8 | 0.7% | Sep 5, 2023 | Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter. |
| CVE-2023-40743 | CRITICAL | 9.8 | 1.9% | Sep 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that lo... |
| CVE-2023-41910 | CRITICAL | 9.8 | 1.0% | Sep 5, 2023 | An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a mal... |
| CVE-2023-28581 | CRITICAL | 9.8 | 0.4% | Sep 5, 2023 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. |
| CVE-2023-28562 | CRITICAL | 9.8 | 0.4% | Sep 5, 2023 | Memory corruption while handling payloads from remote ESL. |
| CVE-2023-28543 | CRITICAL | 9.8 | 0.3% | Sep 5, 2023 | A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted... |
| CVE-2023-35892 | CRITICAL | 9.1 | 0.8% | Sep 5, 2023 | IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attac... |
| CVE-2023-41054 | CRITICAL | 9.1 | 0.7% | Sep 4, 2023 | LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subjec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now