2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-38862CRITICAL9.8An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_43...
CVE-2023-38861CRITICAL9.8An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username par...
CVE-2023-39662CRITICAL9.8An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter ...
CVE-2023-39661CRITICAL9.8An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak functi...
CVE-2023-39659CRITICAL9.8An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted...
CVE-2023-38915CRITICAL9.8File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload...
CVE-2023-38896CRITICAL9.8An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the fro...
CVE-2023-38889CRITICAL9.8An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username...
CVE-2023-38860CRITICAL9.8An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
CVE-2023-35082CRITICAL9.8An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu...
CVE-2023-21287CRITICAL9.8In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code executio...
CVE-2023-21242CRITICAL9.8In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to ...
CVE-2023-20965CRITICAL9.8In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic ...
CVE-2023-3435CRITICAL9.8The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before usi...
CVE-2023-39293CRITICAL9.8A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which co...
CVE-2023-39292CRITICAL9.8A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could ...
CVE-2023-29468CRITICAL9.8The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_...
CVE-2023-32748CRITICAL9.8The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated a...
CVE-2023-40359CRITICAL9.8xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither...
CVE-2023-4322CRITICAL9.8Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-30187CRITICAL9.8An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to...
CVE-2023-30186CRITICAL9.8A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitr...
CVE-2023-37847CRITICAL9.8novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
CVE-2023-3266CRITICAL9.8A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all ...
CVE-2023-3265CRITICAL9.8An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the user...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now