2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26020HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on ...
CVE-2023-24785MEDIUM5.5An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag functio...
CVE-2023-24964MEDIUM5.5IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X...
CVE-2023-24369MEDIUM6.1A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2023-22868MEDIUM5.4IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2023-0895MEDIUM4.9The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘...
CVE-2023-0822HIGH8.8 The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an u...
CVE-2023-23007HIGH7.2An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability...
CVE-2023-24388MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3...
CVE-2023-24329HIGH7.5An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supply...
CVE-2023-23899MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitr...
CVE-2023-23586MEDIUM5.5Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. ...
CVE-2023-0882HIGH8.8Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on...
CVE-2023-0887HIGH7.8A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown proces...
CVE-2023-0883CRITICAL9.8A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulne...
CVE-2023-24221CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMa...
CVE-2023-24220CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMa...
CVE-2023-24219CRITICAL9.8LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMa...
CVE-2023-24078HIGH8.8Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c...
CVE-2023-23695MEDIUM5.9 Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote ...
CVE-2023-0880MEDIUM4.3Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0879MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
CVE-2023-0878MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.
CVE-2023-0877HIGH8.8Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
CVE-2023-0821MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza s...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now