2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53955CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to b...
CVE-2023-47232MEDIUM4.3Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: fr...
CVE-2023-25446HIGH7.7Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured...
CVE-2023-25445MEDIUM5.4Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control...
CVE-2023-25068MEDIUM4.3Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Contr...
CVE-2023-53959CRITICAL9.8FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placin...
CVE-2023-53958HIGH8.6LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT...
CVE-2023-53957HIGH8.8Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malic...
CVE-2023-53956HIGH8.8Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr...
CVE-2023-53954HIGH8.5ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privile...
CVE-2023-53953MEDIUM5.4WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malic...
CVE-2023-53952HIGH8.8Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P...
CVE-2023-53951CRITICAL9.8Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key im...
CVE-2023-53950CRITICAL9.8InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file ...
CVE-2023-53949HIGH8.5AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the P...
CVE-2023-53948CRITICAL9.8Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows ...
CVE-2023-53947HIGH8.5OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile...
CVE-2023-53946HIGH8.5Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow...
CVE-2023-53945HIGH8.8BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitra...
CVE-2023-30971MEDIUM6.8Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.
CVE-2023-53944HIGH7.1EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access fi...
CVE-2023-53943MEDIUM6.9GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers t...
CVE-2023-53942CRITICAL9.4File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious ...
CVE-2023-53941CRITICAL9.8EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute a...
CVE-2023-53940HIGH8.4Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now