2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49967 | HIGH | 7.5 | 0.8% | Dec 7, 2023 | Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xml... |
| CVE-2023-39171 | HIGH | 7.2 | 1.1% | Dec 7, 2023 | SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials. |
| CVE-2023-39167 | HIGH | 7.5 | 1.0% | Dec 7, 2023 | In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensi... |
| CVE-2023-49958 | HIGH | 7.5 | 0.6% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. ... |
| CVE-2023-49957 | HIGH | 7.5 | 0.5% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I... |
| CVE-2023-49956 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A... |
| CVE-2023-49955 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. I... |
| CVE-2023-48861 | HIGH | 7.8 | 0.3% | Dec 7, 2023 | DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitra... |
| CVE-2023-48841 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
| CVE-2023-48840 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. |
| CVE-2023-48835 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
| CVE-2023-48834 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. |
| CVE-2023-48833 | HIGH | 7.5 | 1.1% | Dec 7, 2023 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaus... |
| CVE-2023-48831 | HIGH | 7.5 | 1.2% | Dec 7, 2023 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exha... |
| CVE-2023-48830 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. |
| CVE-2023-48826 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. |
| CVE-2023-48207 | HIGH | 8.8 | 1.2% | Dec 7, 2023 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. |
| CVE-2023-43304 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of... |
| CVE-2023-43303 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via l... |
| CVE-2023-43302 | HIGH | 8.2 | 0.6% | Dec 7, 2023 | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the ... |
| CVE-2023-43301 | HIGH | 8.2 | 0.6% | Dec 7, 2023 | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka... |
| CVE-2023-43300 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ... |
| CVE-2023-46307 | HIGH | 7.5 | 1.3% | Dec 7, 2023 | An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input t... |
| CVE-2023-41106 | HIGH | 7.5 | 0.9% | Dec 7, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. Th... |
| CVE-2023-5761 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now