2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38862 | CRITICAL | 9.8 | 1.1% | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_43... |
| CVE-2023-38861 | CRITICAL | 9.8 | 1.4% | Aug 15, 2023 | An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username par... |
| CVE-2023-39662 | CRITICAL | 9.8 | 1.2% | Aug 15, 2023 | An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter ... |
| CVE-2023-39661 | CRITICAL | 9.8 | 1.2% | Aug 15, 2023 | An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak functi... |
| CVE-2023-39659 | CRITICAL | 9.8 | 1.3% | Aug 15, 2023 | An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted... |
| CVE-2023-38915 | CRITICAL | 9.8 | 0.7% | Aug 15, 2023 | File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload... |
| CVE-2023-38896 | CRITICAL | 9.8 | 1.5% | Aug 15, 2023 | An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the fro... |
| CVE-2023-38889 | CRITICAL | 9.8 | 1.0% | Aug 15, 2023 | An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username... |
| CVE-2023-38860 | CRITICAL | 9.8 | 1.2% | Aug 15, 2023 | An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter. |
| CVE-2023-35082 | CRITICAL | 9.8 | 100.0% | Aug 15, 2023 | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu... |
| CVE-2023-21287 | CRITICAL | 9.8 | 0.4% | Aug 14, 2023 | In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code executio... |
| CVE-2023-21242 | CRITICAL | 9.8 | 0.4% | Aug 14, 2023 | In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to ... |
| CVE-2023-20965 | CRITICAL | 9.8 | 0.6% | Aug 14, 2023 | In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic ... |
| CVE-2023-3435 | CRITICAL | 9.8 | 0.8% | Aug 14, 2023 | The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before usi... |
| CVE-2023-39293 | CRITICAL | 9.8 | 1.4% | Aug 14, 2023 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which co... |
| CVE-2023-39292 | CRITICAL | 9.8 | 0.5% | Aug 14, 2023 | A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could ... |
| CVE-2023-29468 | CRITICAL | 9.8 | 10.1% | Aug 14, 2023 | The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_... |
| CVE-2023-32748 | CRITICAL | 9.8 | 0.9% | Aug 14, 2023 | The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated a... |
| CVE-2023-40359 | CRITICAL | 9.8 | 0.7% | Aug 14, 2023 | xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither... |
| CVE-2023-4322 | CRITICAL | 9.8 | 0.9% | Aug 14, 2023 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. |
| CVE-2023-30187 | CRITICAL | 9.8 | 1.9% | Aug 14, 2023 | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to... |
| CVE-2023-30186 | CRITICAL | 9.8 | 1.8% | Aug 14, 2023 | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitr... |
| CVE-2023-37847 | CRITICAL | 9.8 | 0.7% | Aug 14, 2023 | novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-3266 | CRITICAL | 9.8 | 0.8% | Aug 14, 2023 | A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all ... |
| CVE-2023-3265 | CRITICAL | 9.8 | 1.5% | Aug 14, 2023 | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the user... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now