2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53939MEDIUM5.4TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject m...
CVE-2023-53938MEDIUM5.4RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts t...
CVE-2023-53937HIGH8.5Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 ...
CVE-2023-53936MEDIUM5.1Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ...
CVE-2023-53935MEDIUM5.4WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through ...
CVE-2023-53934HIGH8.7A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requ...
CVE-2023-53738MEDIUM5.4A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scrip...
CVE-2023-53737MEDIUM4.8A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloa...
CVE-2023-53736MEDIUM5.4A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scrip...
CVE-2023-53933HIGH8.8Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious...
CVE-2023-53932MEDIUM5.4Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicio...
CVE-2023-53931MEDIUM6.1Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allow...
CVE-2023-53930HIGH7.5ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to do...
CVE-2023-53929HIGH8phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into...
CVE-2023-53928MEDIUM6.1PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to uplo...
CVE-2023-53927MEDIUM5.4PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in...
CVE-2023-53926CRITICAL9.8PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers ...
CVE-2023-53925MEDIUM6.1UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files w...
CVE-2023-53924HIGH8.8UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo...
CVE-2023-53923CRITICAL9.8UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrati...
CVE-2023-53922CRITICAL9.8TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthe...
CVE-2023-53921CRITICAL9.8SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to...
CVE-2023-53920MEDIUM5.4PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible throug...
CVE-2023-53919MEDIUM5.4PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible thro...
CVE-2023-53918MEDIUM6.1PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible throug...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now