2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-3264CRITICAL9.8The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactio...
CVE-2023-3259CRITICAL9.8The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By man...
CVE-2023-39403CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39402CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39401CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39400CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39399CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39398CRITICAL9.1Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san...
CVE-2023-39385CRITICAL9.1Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnera...
CVE-2023-39405CRITICAL9.8Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability m...
CVE-2023-3452CRITICAL9.8The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w...
CVE-2023-40267CRITICAL9.8GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists becau...
CVE-2023-40254CRITICAL9.8Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Geni...
CVE-2023-40260CRITICAL9.1EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first fa...
CVE-2023-40253CRITICAL9.8Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0...
CVE-2023-3824CRITICAL9.8In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading ...
CVE-2023-40256CRITICAL9.8A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to i...
CVE-2023-27515CRITICAL9.6Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potenti...
CVE-2023-25775CRITICAL9.8Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an una...
CVE-2023-39806CRITICAL9.8iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
CVE-2023-39805CRITICAL9.8iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
CVE-2023-32565CRITICAL9.1An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource...
CVE-2023-32564CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could...
CVE-2023-32563CRITICAL9.8An unauthenticated attacker could achieve the code execution through a RemoteControl server.
CVE-2023-32562CRITICAL9.8An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now