2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53917HIGH8.7Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad...
CVE-2023-53916MEDIUM4.6Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the a...
CVE-2023-53915MEDIUM4.6Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject maliciou...
CVE-2023-53914CRITICAL9.8UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user...
CVE-2023-53913HIGH8.8Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in...
CVE-2023-53912HIGH8.5USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow...
CVE-2023-53911MEDIUM5.4Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows auth...
CVE-2023-53910MEDIUM5.4WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici...
CVE-2023-53909MEDIUM5.4WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici...
CVE-2023-53908HIGH8.8HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol...
CVE-2023-53907HIGH7.1Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logg...
CVE-2023-53906MEDIUM4.8projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to injec...
CVE-2023-53905HIGH8ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in...
CVE-2023-53904MEDIUM5.1Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject m...
CVE-2023-53900MEDIUM6.1Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded exter...
CVE-2023-53896HIGH8.7D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attacke...
CVE-2023-53903MEDIUM5.4WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malic...
CVE-2023-53902HIGH7WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary...
CVE-2023-53901MEDIUM6.1WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to c...
CVE-2023-53899CRITICAL9.8PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in...
CVE-2023-53898MEDIUM5.4Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject ma...
CVE-2023-53897MEDIUM5.4Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to in...
CVE-2023-53895CRITICAL9.8PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts...
CVE-2023-53894CRITICAL9.8phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type com...
CVE-2023-53893MEDIUM6.5Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL pa...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now