2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0070MEDIUM5.4The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attr...
CVE-2023-0062MEDIUM5.4The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes befo...
CVE-2023-0687CRITICAL9.8A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the functi...
CVE-2023-24276CRITICAL9.8TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country para...
CVE-2023-24202CRITICAL9.8Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.p...
CVE-2023-24201CRITICAL9.8Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.
CVE-2023-24200CRITICAL9.8Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
CVE-2023-24199CRITICAL9.8Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.ph...
CVE-2023-24198CRITICAL9.8Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the tick...
CVE-2023-24197MEDIUM6.1Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_orde...
CVE-2023-24195MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet...
CVE-2023-24194MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet...
CVE-2023-24192MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par...
CVE-2023-24191MEDIUM6.1Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par...
CVE-2023-0679HIGH8.1A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been rated as critical. Affected by th...
CVE-2023-22849MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ...
CVE-2023-25193HIGH7.5hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks durin...
CVE-2023-0678MEDIUM5.3Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0677MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0676MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVE-2023-0675HIGH8.8A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an ...
CVE-2023-0674MEDIUM6.5A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some un...
CVE-2023-0673HIGH8.1A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerabili...
CVE-2023-0671HIGH8.8Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-24806Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now