2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-50857HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover ...
CVE-2023-50856HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B...
CVE-2023-36381HIGH8.8Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a throu...
CVE-2023-32795HIGH7.2Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from ...
CVE-2023-27447HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notifica...
CVE-2023-50038HIGH8.8There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of ...
CVE-2023-50692HIGH8.8File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploade...
CVE-2023-46989HIGH7.8SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers...
CVE-2023-50445HIGH7.8Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 ...
CVE-2023-51006HIGH7.5An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified v...
CVE-2023-49230HIGH8.8An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows att...
CVE-2023-49002HIGH7.5An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended acc...
CVE-2023-51080HIGH7.5The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
CVE-2023-51075HIGH7.5hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerabil...
CVE-2023-47882HIGH7.1The Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to ...
CVE-2023-52075HIGH7.5ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f8...
CVE-2023-40038HIGH8.8Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They...
CVE-2023-51697HIGH7.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti...
CVE-2023-51665HIGH7.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti...
CVE-2023-50255HIGH7.8Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerab...
CVE-2023-3171HIGH7.5A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl...
CVE-2023-52096HIGH7.5SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (su...
CVE-2023-6250HIGH7.5The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthe...
CVE-2023-6114HIGH7.5The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listin...
CVE-2023-5939HIGH7.2The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now