CVE Vulnerabilities in 2023

198 documented vulnerabilities published in 2023.

Other years: 2026 2025 2024 2022 2021 2020

Top Affected Vendors in 2023

All CVEs from 2023

CVE-2023-4231
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics Online Payment System allows SQL Injection. This issue affects Online Payment System: before 4.09.

Cevik Informatics Online Payment System Sep 15, 2023
CVE-2023-4830
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allows SQL Injection. This issue affects Signalix: 7T_0228.

Turaconsulting Signalix Sep 15, 2023
CVE-2023-4673
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection. This issue affects Turasistan: before 20230911 .

Sanalogi Turasistan Sep 15, 2023
CVE-2023-4972
9.8 critical

Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This issue affects Digital Yepas: before 1.0.1.

Yepas Digital Yepas Sep 14, 2023
CVE-2023-4702
9.8 critical

Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

Yepas Digital Yepas Sep 14, 2023
CVE-2023-4676
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro allows Reflected XSS. This issue affects MedasPro: before 28.

Yordam Medaspro Sep 14, 2023
CVE-2023-4766
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL Injection. This issue affects Movus: before 20230913.

Movus Movus Sep 14, 2023
CVE-2023-4669
9.8 critical

Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.

Exagate Sysguard 3001 Firmware Sep 14, 2023
CVE-2023-4832
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection. This issue affects Company Management: before 3072 .

Acekaholding Company Management Sep 14, 2023
CVE-2023-40271
7.5 high

In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (def

Trustedfirmware Trusted Firmware-M Sep 8, 2023
CVE-2023-4531
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

Mestav E-Commerce Software Sep 5, 2023
CVE-2023-4178
9.8 critical

Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

Neutron Smart Vms Sep 5, 2023
CVE-2023-4034
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.

Digitatek Smartrise Document Management System Sep 5, 2023
CVE-2023-3616
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.

Mava Hotel Management System Sep 5, 2023
CVE-2023-35072
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .

Coyavtravel Proagent Sep 5, 2023
CVE-2023-35068
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.

Bma Personnel Tracking System Sep 5, 2023
CVE-2023-35065
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.

Osoft Dyeing - Printing - Finishing Production Management Sep 5, 2023
CVE-2023-3375
7.2 high

Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0.

Bookreen Bookreen Sep 5, 2023
CVE-2023-3374
9.8 critical

Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.

Bookreen Bookreen Sep 5, 2023
CVE-2023-3632
9.8 critical

Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: before 6.2.3.

Kunduz Kunduz Aug 9, 2023
CVE-2023-36897
8.1 high

Visual Studio Tools for Office Runtime Spoofing Vulnerability

Microsoft 365 Apps Aug 8, 2023
CVE-2023-3522
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection. This issue affects License Portal System: before 1.48.

A2Technology License Portal System Aug 8, 2023
CVE-2023-3386
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905.

A2Technology Camera Trap Tracking System Aug 8, 2023
CVE-2023-3653
5.4 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS. This issue affects E-Commerce Software: before 11.

Digital-Ant Digital Ant Aug 8, 2023