2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50857 | HIGH | 7.2 | 0.5% | Dec 28, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover ... |
| CVE-2023-50856 | HIGH | 7.2 | 0.5% | Dec 28, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B... |
| CVE-2023-36381 | HIGH | 8.8 | 0.5% | Dec 28, 2023 | Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a throu... |
| CVE-2023-32795 | HIGH | 7.2 | 0.7% | Dec 28, 2023 | Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from ... |
| CVE-2023-27447 | HIGH | 7.5 | 0.5% | Dec 28, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notifica... |
| CVE-2023-50038 | HIGH | 8.8 | 0.8% | Dec 28, 2023 | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of ... |
| CVE-2023-50692 | HIGH | 8.8 | 0.9% | Dec 28, 2023 | File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploade... |
| CVE-2023-46989 | HIGH | 7.8 | 0.2% | Dec 28, 2023 | SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers... |
| CVE-2023-50445 | HIGH | 7.8 | 9.1% | Dec 28, 2023 | Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 ... |
| CVE-2023-51006 | HIGH | 7.5 | 0.6% | Dec 28, 2023 | An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified v... |
| CVE-2023-49230 | HIGH | 8.8 | 2.1% | Dec 28, 2023 | An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows att... |
| CVE-2023-49002 | HIGH | 7.5 | 0.7% | Dec 27, 2023 | An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended acc... |
| CVE-2023-51080 | HIGH | 7.5 | 0.6% | Dec 27, 2023 | The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow. |
| CVE-2023-51075 | HIGH | 7.5 | 0.7% | Dec 27, 2023 | hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerabil... |
| CVE-2023-47882 | HIGH | 7.1 | 0.5% | Dec 27, 2023 | The Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to ... |
| CVE-2023-52075 | HIGH | 7.5 | 0.5% | Dec 27, 2023 | ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f8... |
| CVE-2023-40038 | HIGH | 8.8 | 0.3% | Dec 27, 2023 | Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They... |
| CVE-2023-51697 | HIGH | 7.5 | 0.3% | Dec 27, 2023 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti... |
| CVE-2023-51665 | HIGH | 7.5 | 0.3% | Dec 27, 2023 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti... |
| CVE-2023-50255 | HIGH | 7.8 | 1.1% | Dec 27, 2023 | Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerab... |
| CVE-2023-3171 | HIGH | 7.5 | 0.9% | Dec 27, 2023 | A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl... |
| CVE-2023-52096 | HIGH | 7.5 | 0.6% | Dec 26, 2023 | SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (su... |
| CVE-2023-6250 | HIGH | 7.5 | 0.5% | Dec 26, 2023 | The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthe... |
| CVE-2023-6114 | HIGH | 7.5 | 30.9% | Dec 26, 2023 | The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listin... |
| CVE-2023-5939 | HIGH | 7.2 | 1.3% | Dec 26, 2023 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now