2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53955 | CRITICAL | 9.8 | 0.8% | Dec 22, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to b... |
| CVE-2023-47232 | MEDIUM | 4.3 | 0.2% | Dec 21, 2025 | Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: fr... |
| CVE-2023-25446 | HIGH | 7.7 | 0.3% | Dec 21, 2025 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured... |
| CVE-2023-25445 | MEDIUM | 5.4 | 0.2% | Dec 21, 2025 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control... |
| CVE-2023-25068 | MEDIUM | 4.3 | 0.2% | Dec 21, 2025 | Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2023-53959 | CRITICAL | 9.8 | 0.7% | Dec 19, 2025 | FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placin... |
| CVE-2023-53958 | HIGH | 8.6 | 0.3% | Dec 19, 2025 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT... |
| CVE-2023-53957 | HIGH | 8.8 | 0.5% | Dec 19, 2025 | Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malic... |
| CVE-2023-53956 | HIGH | 8.8 | 0.7% | Dec 19, 2025 | Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr... |
| CVE-2023-53954 | HIGH | 8.5 | 0.1% | Dec 19, 2025 | ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privile... |
| CVE-2023-53953 | MEDIUM | 5.4 | 0.2% | Dec 19, 2025 | WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malic... |
| CVE-2023-53952 | HIGH | 8.8 | 1.0% | Dec 19, 2025 | Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P... |
| CVE-2023-53951 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key im... |
| CVE-2023-53950 | CRITICAL | 9.8 | 0.6% | Dec 19, 2025 | InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file ... |
| CVE-2023-53949 | HIGH | 8.5 | 0.1% | Dec 19, 2025 | AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the P... |
| CVE-2023-53948 | CRITICAL | 9.8 | 0.8% | Dec 19, 2025 | Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows ... |
| CVE-2023-53947 | HIGH | 8.5 | 0.1% | Dec 19, 2025 | OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile... |
| CVE-2023-53946 | HIGH | 8.5 | 0.1% | Dec 19, 2025 | Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow... |
| CVE-2023-53945 | HIGH | 8.8 | 1.0% | Dec 19, 2025 | BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitra... |
| CVE-2023-30971 | MEDIUM | 6.8 | 0.2% | Dec 19, 2025 | Gotham Gaia application was found to be exposing multiple unauthenticated endpoints. |
| CVE-2023-53944 | HIGH | 7.1 | 0.8% | Dec 18, 2025 | EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access fi... |
| CVE-2023-53943 | MEDIUM | 6.9 | 0.3% | Dec 18, 2025 | GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers t... |
| CVE-2023-53942 | CRITICAL | 9.4 | 0.5% | Dec 18, 2025 | File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious ... |
| CVE-2023-53941 | CRITICAL | 9.8 | 5.7% | Dec 18, 2025 | EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute a... |
| CVE-2023-53940 | HIGH | 8.4 | 0.2% | Dec 18, 2025 | Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now