2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53939 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject m... |
| CVE-2023-53938 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts t... |
| CVE-2023-53937 | HIGH | 8.5 | 0.2% | Dec 18, 2025 | Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 ... |
| CVE-2023-53936 | MEDIUM | 5.1 | 0.2% | Dec 18, 2025 | Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ... |
| CVE-2023-53935 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through ... |
| CVE-2023-53934 | HIGH | 8.7 | 0.4% | Dec 18, 2025 | A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requ... |
| CVE-2023-53738 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scrip... |
| CVE-2023-53737 | MEDIUM | 4.8 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloa... |
| CVE-2023-53736 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scrip... |
| CVE-2023-53933 | HIGH | 8.8 | 0.9% | Dec 17, 2025 | Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious... |
| CVE-2023-53932 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicio... |
| CVE-2023-53931 | MEDIUM | 6.1 | 2.3% | Dec 17, 2025 | Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allow... |
| CVE-2023-53930 | HIGH | 7.5 | 0.3% | Dec 17, 2025 | ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to do... |
| CVE-2023-53929 | HIGH | 8 | 0.4% | Dec 17, 2025 | phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into... |
| CVE-2023-53928 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to uplo... |
| CVE-2023-53927 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in... |
| CVE-2023-53926 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers ... |
| CVE-2023-53925 | MEDIUM | 6.1 | 0.3% | Dec 17, 2025 | UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files w... |
| CVE-2023-53924 | HIGH | 8.8 | 0.8% | Dec 17, 2025 | UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo... |
| CVE-2023-53923 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrati... |
| CVE-2023-53922 | CRITICAL | 9.8 | 0.9% | Dec 17, 2025 | TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthe... |
| CVE-2023-53921 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to... |
| CVE-2023-53920 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible throug... |
| CVE-2023-53919 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible thro... |
| CVE-2023-53918 | MEDIUM | 6.1 | 0.3% | Dec 17, 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible throug... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now