2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32560 | CRITICAL | 9.8 | 98.9% | Aug 10, 2023 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup... |
| CVE-2023-38034 | CRITICAL | 9.8 | 1.0% | Aug 10, 2023 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Swi... |
| CVE-2023-35085 | CRITICAL | 9.8 | 0.7% | Aug 10, 2023 | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Mon... |
| CVE-2023-32567 | CRITICAL | 9.8 | 2.1% | Aug 10, 2023 | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 |
| CVE-2023-32566 | CRITICAL | 9.1 | 2.1% | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2023-39966 | CRITICAL | 9.8 | 0.7% | Aug 10, 2023 | 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr... |
| CVE-2023-36311 | CRITICAL | 9.8 | 0.7% | Aug 10, 2023 | There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0... |
| CVE-2023-39776 | CRITICAL | 9.8 | 0.9% | Aug 10, 2023 | A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uplo... |
| CVE-2023-37734 | CRITICAL | 9.8 | 1.1% | Aug 10, 2023 | EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow. |
| CVE-2023-37069 | CRITICAL | 9.8 | 0.8% | Aug 10, 2023 | Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attac... |
| CVE-2023-26311 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | A remote code execution vulnerability in the webview component of OPPO Store app. |
| CVE-2023-26309 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | A remote code execution vulnerability in the webview component of OnePlus Store app. |
| CVE-2023-30699 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows cod... |
| CVE-2023-33241 | CRITICAL | 9.1 | 1.0% | Aug 9, 2023 | Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by... |
| CVE-2023-37068 | CRITICAL | 9.8 | 0.9% | Aug 9, 2023 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, l... |
| CVE-2023-33468 | CRITICAL | 9.1 | 0.6% | Aug 9, 2023 | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables ... |
| CVE-2023-39008 | CRITICAL | 9.8 | 2.6% | Aug 9, 2023 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 ... |
| CVE-2023-39007 | CRITICAL | 9.6 | 2.3% | Aug 9, 2023 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al... |
| CVE-2023-39004 | CRITICAL | 9.8 | 0.8% | Aug 9, 2023 | Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edit... |
| CVE-2023-39001 | CRITICAL | 9.8 | 3.0% | Aug 9, 2023 | A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Busines... |
| CVE-2023-39969 | CRITICAL | 9.8 | 0.5% | Aug 9, 2023 | uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of ... |
| CVE-2023-34545 | CRITICAL | 9.8 | 0.6% | Aug 9, 2023 | A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or t... |
| CVE-2023-3632 | CRITICAL | 9.8 | 0.6% | Aug 9, 2023 | Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App al... |
| CVE-2023-33934 | CRITICAL | 9.1 | 1.1% | Aug 9, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Tr... |
| CVE-2023-26310 | CRITICAL | 9.8 | 1.0% | Aug 9, 2023 | There is a command injection problem in the old version of the mobile phone backup app. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now