2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-32560CRITICAL9.8An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup...
CVE-2023-38034CRITICAL9.8A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Swi...
CVE-2023-35085CRITICAL9.8An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Mon...
CVE-2023-32567CRITICAL9.8Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
CVE-2023-32566CRITICAL9.1An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource...
CVE-2023-39966CRITICAL9.81Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr...
CVE-2023-36311CRITICAL9.8There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0...
CVE-2023-39776CRITICAL9.8A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uplo...
CVE-2023-37734CRITICAL9.8EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
CVE-2023-37069CRITICAL9.8Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attac...
CVE-2023-26311CRITICAL9.8 A remote code execution vulnerability in the webview component of OPPO Store app.
CVE-2023-26309CRITICAL9.8A remote code execution vulnerability in the webview component of OnePlus Store app.
CVE-2023-30699CRITICAL9.8Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows cod...
CVE-2023-33241CRITICAL9.1Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by...
CVE-2023-37068CRITICAL9.8Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, l...
CVE-2023-33468CRITICAL9.1KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables ...
CVE-2023-39008CRITICAL9.8A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 ...
CVE-2023-39007CRITICAL9.6/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al...
CVE-2023-39004CRITICAL9.8Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edit...
CVE-2023-39001CRITICAL9.8A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Busines...
CVE-2023-39969CRITICAL9.8uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of ...
CVE-2023-34545CRITICAL9.8A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or t...
CVE-2023-3632CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App al...
CVE-2023-33934CRITICAL9.1Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Tr...
CVE-2023-26310CRITICAL9.8There is a command injection problem in the old version of the mobile phone backup app.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now