CVE Vulnerabilities in 2023

198 documented vulnerabilities published in 2023.

Other years: 2026 2025 2024 2022 2021 2020

Top Affected Vendors in 2023

All CVEs from 2023

CVE-2023-28531
9.8 critical

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

Openbsd Openssh Mar 17, 2023
CVE-2023-0322
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS. This issue affects UNIS: before 28376.

Talentyazilim Unis Mar 15, 2023
CVE-2023-23398
7.1 high

Microsoft Excel Spoofing Vulnerability

Microsoft 365 Apps Mar 14, 2023
CVE-2023-23391
5.5 medium

Office for Android Spoofing Vulnerability

Microsoft Office Mar 14, 2023
CVE-2022-23791
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS). This issue affects Customer Relation Manager: before 2022.03.13.

Firmanet Customer Relation Manager Mar 14, 2023
CVE-2022-23790
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS). This issue affects Customer Relation Manager: before 2022.03.13.

Firmanet Technology Customer Relation Manager Mar 14, 2023
CVE-2023-1246
7.5 high

Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.

Saysis Starcities Mar 10, 2023
CVE-2023-1198
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.

Saysis Starcities Mar 10, 2023
CVE-2023-1091
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.

Alpatateknoloji Licensed Warehousing Automation System Mar 10, 2023
CVE-2023-1251
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.

Akinsoft Wolvox Mar 9, 2023
CVE-2023-1267
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1.

Pttemkart Pttem Kart Mar 8, 2023
CVE-2022-3760
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.

Miateknoloji Mia-Med Mar 7, 2023
CVE-2023-0979
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.

Meddatapacs Meddatapacs Mar 6, 2023
CVE-2022-2178
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saysis Computer Starcities allows Cross-Site Scripting (XSS). This issue affects Starcities: before 1.1.

Saysis Starcities Mar 6, 2023
CVE-2023-0839
9.8 critical

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1.

Inscada Project Inscada Mar 6, 2023
CVE-2023-0578
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies Book Cites allows Cross-Site Scripting (XSS). This issue affects Book Cites: before 23.01.05.

Asosegitim Bookcites Mar 3, 2023
CVE-2023-0577
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies SOBIAD allows Cross-Site Scripting (XSS). This issue affects SOBIAD: before 23.02.01.

Asosegitim Sobiad Mar 3, 2023
CVE-2023-1114
9.8 critical

Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.

Eskom E-Belediye Mar 1, 2023
CVE-2023-1064
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.

Uzaybaskul Weighbridge Automation Software Mar 1, 2023
CVE-2022-2504
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.

Sdd-Baro Project Sdd-Baro Feb 23, 2023
CVE-2023-0939
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.

Online Services Project Online Services Feb 23, 2023
CVE-2023-26314
8.8 high

The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

Mono-Project Mono Feb 22, 2023
CVE-2023-0882
8.8 high

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16.

Krontech Single Connect Feb 17, 2023
CVE-2023-25136
6.5 medium

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-pa

Openbsd Openssh Feb 3, 2023