2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-53892HIGH7.2Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malic...
CVE-2023-53891MEDIUM5.4Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou...
CVE-2023-53890MEDIUM5.4Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious S...
CVE-2023-53889HIGH7.2Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrar...
CVE-2023-53888HIGH8.8Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arb...
CVE-2023-53887MEDIUM5.4Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts wh...
CVE-2023-53886HIGH7.5Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that all...
CVE-2023-53885HIGH7.2Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP file...
CVE-2023-53884MEDIUM5.4Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload m...
CVE-2023-53883HIGH7.2Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject sys...
CVE-2023-53882MEDIUM5.1JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attack...
CVE-2023-53881HIGH8.1ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manip...
CVE-2023-53880MEDIUM4.8Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2023-53879MEDIUM5.5NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attacker...
CVE-2023-53878MEDIUM6.9Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP ...
CVE-2023-53877CRITICAL9.8Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to ma...
CVE-2023-53876MEDIUM5.4Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with ...
CVE-2023-53875HIGH8.8GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows att...
CVE-2023-53874CRITICAL9.8GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows att...
CVE-2023-53873HIGH8.7SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attacker...
CVE-2023-53872CRITICAL9.3Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execu...
CVE-2023-53871CRITICAL9.8Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PH...
CVE-2023-53870MEDIUM5.1Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to ...
CVE-2023-53869HIGH8.7WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute danger...
CVE-2023-53868HIGH8.8Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload m...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now