CVE Vulnerabilities in 2023

198 documented vulnerabilities published in 2023.

Other years: 2026 2025 2024 2022 2021 2020

Top Affected Vendors in 2023

All CVEs from 2023

CVE-2023-2885
8.1 high

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM).This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2884
9.8 critical

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2883
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2882
9.8 critical

Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2064
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection.This issue affects eTrace: before 23.05.20.

Minovateknoloji Etrace May 24, 2023
CVE-2023-2045
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection.This issue affects Auto Damage Tracking Software: before 4.

Ipekyolunet Software Auto Damage Tracking Software May 24, 2023
CVE-2023-2065
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .

Armoli Cargo Tracking System May 24, 2023
CVE-2023-2750
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection.This issue affects E-municipality: before 6.05.

Cityboss E-Municipality May 24, 2023
CVE-2023-1508
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.

Adampos Mobilmen El Terminali Yazilimi May 23, 2023
CVE-2023-2703
7.5 high

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users.This issue affects Competition Management System: before 23.07.

Finexmedia Competition Management System May 23, 2023
CVE-2023-2702
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass.This issue affects Competition Management System: before 23.07.

Finexmedia Competition Management System May 23, 2023
CVE-2023-2713
9.8 critical

Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental Module: before 23.05.15.

Rental Module Project Rental Module May 20, 2023
CVE-2023-2712
9.8 critical

Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.

Rental Module Project Rental Module May 20, 2023
CVE-2023-31409
5.3 medium

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-31408
5.3 medium

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23450
6.2 medium

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23449
5.3 medium

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23448
5.3 medium

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23447
7.5 high

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23446
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23445
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-29335
7.5 high

Microsoft Word Security Feature Bypass Vulnerability

Microsoft Windows 10 1507 May 9, 2023
CVE-2023-29333
3.3 low

Microsoft Access Denial of Service Vulnerability

Microsoft 365 Apps May 9, 2023
CVE-2023-26246
7.8 high

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the digital signature check. This indirectly allows an attacker

Hyundai Gen5W L Firmware Apr 27, 2023