2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53917 | HIGH | 8.7 | 0.3% | Dec 17, 2025 | Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad... |
| CVE-2023-53916 | MEDIUM | 4.6 | 0.3% | Dec 17, 2025 | Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the a... |
| CVE-2023-53915 | MEDIUM | 4.6 | 0.3% | Dec 17, 2025 | Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject maliciou... |
| CVE-2023-53914 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user... |
| CVE-2023-53913 | HIGH | 8.8 | 0.6% | Dec 17, 2025 | Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in... |
| CVE-2023-53912 | HIGH | 8.5 | 0.1% | Dec 17, 2025 | USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow... |
| CVE-2023-53911 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows auth... |
| CVE-2023-53910 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici... |
| CVE-2023-53909 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici... |
| CVE-2023-53908 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol... |
| CVE-2023-53907 | HIGH | 7.1 | 0.7% | Dec 17, 2025 | Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logg... |
| CVE-2023-53906 | MEDIUM | 4.8 | 0.3% | Dec 17, 2025 | projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to injec... |
| CVE-2023-53905 | HIGH | 8 | 0.4% | Dec 17, 2025 | ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in... |
| CVE-2023-53904 | MEDIUM | 5.1 | 0.2% | Dec 17, 2025 | Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject m... |
| CVE-2023-53900 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded exter... |
| CVE-2023-53896 | HIGH | 8.7 | 0.6% | Dec 16, 2025 | D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attacke... |
| CVE-2023-53903 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malic... |
| CVE-2023-53902 | HIGH | 7 | 0.9% | Dec 16, 2025 | WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary... |
| CVE-2023-53901 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to c... |
| CVE-2023-53899 | CRITICAL | 9.8 | 0.5% | Dec 16, 2025 | PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in... |
| CVE-2023-53898 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject ma... |
| CVE-2023-53897 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to in... |
| CVE-2023-53895 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts... |
| CVE-2023-53894 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type com... |
| CVE-2023-53893 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL pa... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now